
Warning: Critical server-side template injection vulnerability in #ERPNext. CVE-2026-72911 CVSS: 9.9. An authenticated user with a common operational role could inject template expressions, leading to arbitrary server-side code execution. #RCE! #Patch #Patch #Patch
Post summary
A critical server‑side template injection vulnerability (CVE‑2026‑72911) with a CVSS of 9.9 has been disclosed for ERPNext; no PoC, exploit, or active exploitation evidence is present, and patch details are not provided.
