CRITICAL
9.9 CVE-2026-65974 Published 17 Aug 2026
ERPNext Server-Side Template Injection Leads to Remote Code Execution
Worried this affects your website?
ERPNext, a free and open source Enterprise Resource Planning tool, is affected by a server-side template injection vulnerability that can lead to remote code execution.
Prior to versions 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without forcing restrict_globals.
- Affected versions: before 15.111.0 and before 16.22.0
- Impact: server-side template injection and remote code execution
- Fixed in: 15.111.0 and 16.22.0
Reference: CVE-2026-65974 on NVD
← Back to Security News