{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-13227", "assignerOrgId": "84fe0718-d6bb-4716-a7e8-81a6d1daa869", "state": "PUBLISHED", "assignerShortName": "Fluid Attacks", "dateReserved": "2026-06-24T16:42:20.788Z", "datePublished": "2026-08-04T20:53:53.785Z", "dateUpdated": "2026-08-04T20:53:53.785Z" }, "containers": { "cna": { "affected": [ { "defaultStatus": "unaffected", "platforms": [ "Windows", "MacOS", "Linux" ], "product": "ERPNext", "vendor": "Frappe", "versions": [ { "lessThan": "15.115.0", "status": "affected", "version": "0", "versionType": "custom" }, { "lessThan": "16.26.0", "status": "affected", "version": "0", "versionType": "custom" } ] } ], "cpeApplicability": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:frappe:erpnext:*:*:windows:*:*:*:*:*", "versionEndExcluding": "15.115.0", "versionStartIncluding": "0", "vulnerable": true }, { "criteria": "cpe:2.3:a:frappe:erpnext:*:*:macos:*:*:*:*:*", "versionEndExcluding": "15.115.0", "versionStartIncluding": "0", "vulnerable": true }, { "criteria": "cpe:2.3:a:frappe:erpnext:*:*:linux:*:*:*:*:*", "versionEndExcluding": "15.115.0", "versionStartIncluding": "0", "vulnerable": true }, { "criteria": "cpe:2.3:a:frappe:erpnext:*:*:windows:*:*:*:*:*", "versionEndExcluding": "16.26.0", "versionStartIncluding": "0", "vulnerable": true }, { "criteria": "cpe:2.3:a:frappe:erpnext:*:*:macos:*:*:*:*:*", "versionEndExcluding": "16.26.0", "versionStartIncluding": "0", "vulnerable": true }, { "criteria": "cpe:2.3:a:frappe:erpnext:*:*:linux:*:*:*:*:*", "versionEndExcluding": "16.26.0", "versionStartIncluding": "0", "vulnerable": true } ], "negate": false, "operator": "OR" } ], "operator": "OR" } ], "credits": [ { "lang": "en", "type": "finder", "value": "Eduardo Ferguson" } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "
An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities.
This issue affects ERPNext: before 15.115.0, before 16.26.0.
" } ], "value": "An Improper Authorization vulnerability exists in ERPNext version