CVE-2026-44447Disclosure(frappe / erpnext)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This vulnerability is fixed in 16.9.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • erpnext

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-05-13); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
erpnext

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-13: 1Mentions · 2026-05-14: 1Mentions · 2026-05-15: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-15: 105-1305-1405-15
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • CyStack@CyStackSecurity
    Disclosure

    📣 SECURITY ADVISORY: Researcher vnth4nhnt from @CyStackSecurity discovered 3 vulnerabilities in ERPNext (Frappe) - CVE-2026-44442, CVE-2026-44446, CVE-2026-44447 Severity: Critical (CVSS 9.9) & High (CVSS 8.8) Details: https://cystack.net/disclosures #CyStack #ERPNext #SQLInjection https://t.co/tMCHV02aJX

    Post summary

    The tweet serves as a security advisory announcing three newly discovered CVEs in ERPNext, giving severity ratings but lacking PoC, exploit, or mitigation details.

    0001075
    3.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-44447 SQL Injection Vulnerability in ERPNext Prior to Version 16.9.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44447 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The text alerts about an SQL injection vulnerability in ERPNext versions before 16.9.0, linking to a vulnerability details page and notification.

    0000049
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44447 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through specially crafted reques… https://www.cve.org/CVERecord?id=CVE-2026-44447

    Post summary

    ERPNext before 16.9.0 exposes vulnerable endpoints to SQL injection (CVE‑2026‑44447); no PoC, exploit, or patch details are shared.

    0000084
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfrappeerpnext---

Explore more