CVE-2026-13227Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-05); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-05: 2Mentions · 2026-08-25: 1Technical Details · 2026-08-05: 208-0508-25
Signal classification1 categories
Disclosure
3100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-052
Disclosure2
2026-08-251
Disclosure1
Full discourse3 posts
  • Fluid Attacks@fluidattacks
    Disclosure

    Fluid Attacks' research team found a zero-day vulnerability in ERPNext. As a #CNA, we assigned the ID CVE-2026-13227. Details here: 🔗 https://fluidattacks.com/advisories/kraviz. We have disclosed 264 #CVE to this date: 🔗https://fluidattacks.com/advisories/. https://t.co/fttaeSFx6h

    Post summary

    Fluid Attacks announced the discovery of a zero‑day vulnerability in ERPNext, assigned CVE-2026-13227, and linked to an advisory for details.

    00010144
    891 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-13227 An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method http://erpnext.cr… https://www.cve.org/CVERecord?id=CVE-2026-13227 ----- Traducción: CVE-2… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-13227, an Improper Authorization flaw in certain ERPNext versions due to insufficient access control in a whitelisted API endpoint.

    0000050
    97 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-13227 An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method http://erpnext.cr… https://www.cve.org/CVERecord?id=CVE-2026-13227

    Post summary

    An Improper Authorization vulnerability was identified in ERPNext versions prior to v16.25.0 and 15.115.0 due to insufficient access control on a whitelisted API method.

    00000707
    57.9K followersView on X

Explore more