CVE-2026-72907Medium· 6.5▾ SunlitERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function in erpnext/accounts/utils.py accepts the ignore_permissions argument without enforcing Account create permission, all…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function in erpnext/accounts/utils.py accepts the ignore_permissions argument without enforcing Account create permission, allowing an authenticated limited user to create unauthorized accounting master records and affect financial data integrity and audit trails. This issue is fixed in versions 15.111.0 and 16.22.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-79917Medium· 6.5MaxKB is an open-source AI assistant for enterprise
CVE-2026-63330High· 7.7Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux
CVE-2026-94379Medium· 6.9The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths
CVE-2026-94152Medium· 4.3A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025
CVE-2026-93961Medium· 5.3A security flaw has been discovered in Dromara UJCMS up to 12.3.1
CVE-2026-93955Medium· 4.3A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1