HIGH

CVE-2026-13227

2026-08-04 CVSS v4.0
CVSS
7.1

Description

An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities.

This issue affects ERPNext: before 15.115.0, before 16.26.0.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

0.25%
Probability of exploitation in next 30 days
16.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE