What is CVE-2026-72911?
CVE-2026-72911 is an unrestricted code execution vulnerability during template rendering in the open-source ERP tool ERPNext. It affects versions prior to 15.118.0 and 16.29.0, specifically through the `validate_template` and `render_template` calls in the `process_statement_of_accounts` module. Immediate update to the fixed versions is recommended.
Azərbaycanca: CVE-2026-72911 ERPNext açıq mənbəli ERP alətində template render zamanı məhdudiyyətsiz icra zəifliyidir. Versiya 15.118.0 və 16.29.0-dan əvvəlki versiyalar, xüsusilə `process_statement_of_accounts` modulundakı `validate_template` və `render_template` çağırışları vasitəsilə təsirlənir. Dərhal göstərilən versiyalara yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of ERPNext are affected by CVE-2026-72911?
CVE-2026-72911 affects ERPNext versions prior to 15.118.0 and versions prior to 16.29.0.
Through which module is CVE-2026-72911 exploited in ERPNext?
This vulnerability is exploited through the `validate_template` and `render_template` calls in the `process_statement_of_accounts` module.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.