CVE-2026-27471General(frappe / erpnext)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch frappe erpnext systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-306CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • erpnext

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • General: 4 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 5 mentions (2026-02-24); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
erpnext

1 version affected across 1 product

Deep dive

Activity timeline8 mentions / 4d
01345Mentions · 2026-02-23: 1Mentions · 2026-02-24: 5Mentions · 2026-05-14: 1Mentions · 2026-08-27: 1Patch / Workaround · 2026-02-23: 1Patch / Workaround · 2026-02-24: 2Technical Details · 2026-02-23: 1Technical Details · 2026-02-24: 202-2302-2405-1408-27
Signal classification3 categories
General
450.0%
Patch
337.5%
Disclosure
112.5%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-231
Patch1
2026-02-245
Disclosure1General2Patch2
2026-05-141
General1
2026-08-271
General1
Full discourse8 posts
  • BugBunny.ai - Continuous AI Pentesting System@BugBunny_ai
    General

    66 CVE-2025-58434 CVE-2025-59057 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-64756 CVE-2026-21884 CVE-2026-22807 CVE-2026-23630 CVE-2026-27471 CVE-2026-27806 CVE-2026-27955 CVE-2026-28215 CVE-2026-28217 CVE-2026-28351 CVE-2026-28361 CVE-2026-28384 CVE-2026-28396 CVE-2026-28398 CVE-2026-28444 CVE-2026-28445 CVE-2026-29093 CVE-2026-30973 CVE-2026-31888 CVE-2026-33016 CVE-2026-33037 CVE-2026-33038 CVE-2026-33039 CVE-2026-3351 CVE-2026-34037 CVE-2026-34158 CVE-2026-34167 CVE-2026-34170 CVE-2026-34171 CVE-2026-34198 CVE-2026-34532 CVE-2026-34573 CVE-2026-34574 CVE-2026-34595 CVE-2026-34746 CVE-2026-34748 CVE-2026-34749 CVE-2026-34750 CVE-2026-34972 CVE-2026-35214 CVE-2026-35412 CVE-2026-35413 CVE-2026-35441 CVE-2026-40165 CVE-2026-40293 CVE-2026-40302 CVE-2026-40304 CVE-2026-40454 CVE-2026-40914 CVE-2026-41131 CVE-2026-41590 CVE-2026-42883 CVE-2026-42884 CVE-2026-42885 CVE-2026-42886 CVE-2026-43888 CVE-2026-43889 CVE-2026-43998 CVE-2026-43999 CVE-2026-4800

    Post summary

    The text lists a series of CVE identifiers without providing any context, details, or actionable information regarding the vulnerabilities.

    2176862729382.1K
    3.1K followersView on X
  • BugBunny.ai - Continuous AI Pentesting System@BugBunny_ai
    General

    108 CVE-2025-58434 CVE-2025-59057 CVE-2025-59343 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-62228 CVE-2025-62232 CVE-2025-64756 CVE-2026-21884 CVE-2026-22706 CVE-2026-22807 CVE-2026-23630 CVE-2026-24015 CVE-2026-24899 CVE-2026-27471 CVE-2026-27806 CVE-2026-27955 CVE-2026-28215 CVE-2026-28217 CVE-2026-28351 CVE-2026-28361 CVE-2026-28384 CVE-2026-28396 CVE-2026-28398 CVE-2026-28444 CVE-2026-28445 CVE-2026-29093 CVE-2026-30973 CVE-2026-31888 CVE-2026-33016 CVE-2026-33037 CVE-2026-33038 CVE-2026-33039 CVE-2026-33264 CVE-2026-33413 CVE-2026-3351 CVE-2026-34037 CVE-2026-34158 CVE-2026-34167 CVE-2026-34170 CVE-2026-34171 CVE-2026-34198 CVE-2026-34532 CVE-2026-34573 CVE-2026-34574 CVE-2026-34595 CVE-2026-34746 CVE-2026-34748 CVE-2026-34749 CVE-2026-34750 CVE-2026-34972 CVE-2026-35214 CVE-2026-35412 CVE-2026-35413 CVE-2026-35441 CVE-2026-40006 CVE-2026-40007 CVE-2026-40009 CVE-2026-40165 CVE-2026-40293 CVE-2026-40302 CVE-2026-40304 CVE-2026-40452 CVE-2026-40454 CVE-2026-40914 CVE-2026-41131 CVE-2026-41590 CVE-2026-42275 CVE-2026-42883 CVE-2026-42884 CVE-2026-42885 CVE-2026-42886 CVE-2026-43888 CVE-2026-43889 CVE-2026-43998 CVE-2026-43999 CVE-2026-44247 CVE-2026-44309 CVE-2026-44310 CVE-2026-44442 CVE-2026-44446 CVE-2026-44705 CVE-2026-44947 CVE-2026-45022 CVE-2026-45090 CVE-2026-45720 CVE-2026-45723 CVE-2026-45726 CVE-2026-46553 CVE-2026-46554 CVE-2026-47733 CVE-2026-4800 CVE-2026-48978 CVE-2026-49478 CVE-2026-50285 CVE-2026-52808 CVE-2026-52809 CVE-2026-53926 CVE-2026-53928 CVE-2026-53929 CVE-2026-53930 CVE-2026-56842 CVE-2026-60076 CVE-2026-60077 CVE-2026-75605 CVE-2026-9103

    Post summary

    The text is a list of CVE identifiers without additional context or detail.

    30124138.4K
    4.0K followersView on X
  • Z A D D Y@Zaddyzaddy
    Patch

    Using Bugbunny 🐰 we found and reported a critical vulnerability affecting ERPNext (CVE-2026-27471), Orgs running versions earlier than <v16.6.1 should patch immediately. Will do a detailed breakdown later

    Post summary

    A critical vulnerability (CVE-2026-27471) in ERPNext has been reported; organizations using versions older than v16.6.1 should patch immediately.

    01061197
    3.1K followersView on X
  • A͓͓͓͓͓͓͓͓͓͓͓͓͓͓͓͓͓͓͓͓͓͓͓͓͓͓͓͓͓͓rthur͛͛͛͛͛͛ Gervais@HatforceSec
    Patch

    Oh, another CVE-2026-27471 reported and patched @ERPNext Unauthorized Document Access via Missing Validation That's ranked Critical: CVSS 9.3 out of 10, not bad @Zaddyzaddy is back at the game

    Post summary

    CVE-2026-27471, an unauthorized document access vulnerability in ERPNext, has been reported and patched, with a CVSS score of 9.3.

    01240656
    3.5K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: A critical improper access control vulnerability in #ERPNext allows unauthorized document access over the network. #CVE-2026-27471 CVSS: 9.3. #Patch #Patch #Patch. More info: https://github.com/frappe/erpnext/security/advisories/GHSA-wpfx-jw7g-7f83

    Post summary

    A critical improper access control flaw in ERPNext (CVE-2026-27471) allows unauthorized document access; a patch is available via the provided advisory link.

    00001341
    7.2K followersView on X
  • BugBunny.ai - Vibehacking for Vibecoders@BugBunny_ai
    General

    yes, here we go again: https://bugbunny.ai/blog/CVE-2026-27471

    Post summary

    The text merely references a blog link for CVE-2026-27471 without providing any substantive details about the vulnerability, PoC, or mitigation.

    0000070
    37 followersView on X
  • BugBunny.ai - Vibehacking for Vibecoders@BugBunny_ai
    General

    @Michael30254744 @Zaddyzaddy yes, here's another one: https://bugbunny.ai/blog/CVE-2026-27471

    Post summary

    The tweet merely points to a blog post about CVE-2026-27471 without providing any additional information or context.

    0000043
    37 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-27471 - Critical ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for... https://www.thehackerwire.com/vulnerability/CVE-2026-27471/ https://t.co/shdVIF1qjR

    Post summary

    The post announces CVE-2026-27471 as a critical flaw in ERP, noting that missing access validation on certain endpoints allows exploitation, and provides a link to a detailed article.

    0000068
    113 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appfrappeerpnext---
Appfrappeerpnext16.0.0--
Appfrappeerpnext16.0.0--
Appfrappeerpnext16.0.0--

Explore more