---
id: CVE-2026-72909
title: ERPNext is a free and open source Enterprise Resource Planning tool
summary: >-
  ERPNext is a free and open source Enterprise Resource Planning tool. Prior to
  15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions path in
  erpnext/accounts/report/accounts_receivable/accounts_receivable.py does not
  apply …
severity: none
cwe:
  - CWE-284
published: '2026-08-10'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:55:04.493'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-72909'
references:
  - url: >-
      https://github.com/frappe/erpnext/commit/b05abbc53b3655b02db17ba2e8165519f195c1c2
    label: security-advisories@github.com
  - url: >-
      https://github.com/frappe/erpnext/commit/c03a66a1bf48a53c42d01c9d936d9b22aa013e11
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/erpnext/pull/55696'
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/erpnext/releases/tag/v15.112.0'
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/erpnext/releases/tag/v16.23.0'
    label: security-advisories@github.com
  - url: 'https://github.com/frappe/erpnext/security/advisories/GHSA-p577-cxv9-h82f'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00473
epssPercentile: 0.384
ingestedAt: '2026-09-09T21:22:45.526Z'
---

## Overview

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions path in erpnext/accounts/report/accounts_receivable/accounts_receivable.py does not apply Customer and Supplier user permissions to the Payment Ledger Entry dynamic-link party field, allowing any authenticated user to read unauthorized cross-company financial data in Accounts Receivable and Accounts Payable reports. This issue is fixed in versions 15.112.0 and 16.23.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
