{"id":"CVE-2026-107841","title":"pacioli provides least-privilege governance and a governed agent broker for ERPNext","summary":"pacioli provides least-privilege governance and a governed agent broker for ERPNext. From version 0.9.6 until version 0.10.0, the pacioli-guard document-layer consent gate allows nested cancellation operations to ride any consent establi…","severity":"medium","cvss":5.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","cwe":["CWE-863"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T19:16:41.900","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107841","references":[{"url":"https://github.com/john-broadway/pacioli/commit/f3c7219f5dde6050bd7921e0ac55afd02771250c","label":"security-advisories@github.com"},{"url":"https://github.com/john-broadway/pacioli/releases/tag/guard-v0.10.0","label":"security-advisories@github.com"},{"url":"https://github.com/john-broadway/pacioli/security/advisories/GHSA-3hj7-6vmj-h8v4","label":"security-advisories@github.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107841"},{"url":"https://github.com/advisories/GHSA-3hj7-6vmj-h8v4"}],"tags":["nvd","ghsa","pip"],"ingestedAt":"2026-10-09T19:09:33.757Z","aliases":["GHSA-3hj7-6vmj-h8v4"],"ecosystem":"pip","vendor":"pacioli-guard","product":"pacioli-guard","affected":["pacioli-guard >= 0.9.6, < 0.10.0"],"patched":["pacioli-guard 0.10.0"],"slug":"CVE-2026-107841","body":"## Overview\n\npacioli provides least-privilege governance and a governed agent broker for ERPNext. From version 0.9.6 until version 0.10.0, the pacioli-guard document-layer consent gate allows nested cancellation operations to ride any consent established by an enclosing governed act without checking whether the marker authorizes cancellation. A credential with API Key Scope.require_consent can submit a caller-controlled Sales Invoice or other supported document under a valid human-minted submit marker and reach Document.cancel() for a different pre-existing submitted document, bypassing the marker's document and act binding, single-use spend, and denial audit. The unauthorized cancellation can reverse the target document's ledger effect; principals without a consent-gated grant are not affected. This issue is fixed in version 0.10.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-107841)\n\nAffected packages:\n\n- `pacioli-guard >= 0.9.6, < 0.10.0`\n\nPatched in:\n\n- `pacioli-guard 0.10.0`\n\nSource: https://github.com/advisories/GHSA-3hj7-6vmj-h8v4","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":31.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}