CVE-2026-27471

Severity CVSS v4.0:
CRITICAL
Type:
CWE-284 Improper Access Control
Publication date:
21/02/2026
Last modified:
21/02/2026

Description

ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1.