medium · CVSS v3 6.4 · CVSS v4 5.3
CVE-2026-96672
Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values refere…
Description
Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call(). Accounts Managers can supply arbitrary dotted Python paths to invoke non-whitelisted internal server-side methods and read their return values.
Scores
- Severity
- medium
- CVSS v2
- 5.5
- CVSS v3
- 6.4
- CVSS v4
- 5.3
- EPSS
- —