CRITICAL 9.9 CVE-2026-65974 Published 17 Aug 2026

ERPNext Server-Side Template Injection Leads to Remote Code Execution

Worried this affects your website?

ERPNext, a free and open source Enterprise Resource Planning tool, is affected by a server-side template injection vulnerability that can lead to remote code execution.

Prior to versions 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without forcing restrict_globals.

  • Affected versions: before 15.111.0 and before 16.22.0
  • Impact: server-side template injection and remote code execution
  • Fixed in: 15.111.0 and 16.22.0

Reference: CVE-2026-65974 on NVD

← Back to Security News