CVE-2026-65822
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
17/08/2026
Last modified:
17/08/2026
Description
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/report/inactive_customers/inactive_customers.py accepts an unvalidated doctype filter and interpolates it into raw SQL in get_sales_details and get_last_sales_amt, allowing an authenticated user to extract sensitive information and manipulate database queries. This issue is fixed in versions 15.116.0 and 16.23.0.
Impact
Base Score 3.x
7.60
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/frappe/erpnext/commit/29dd6e6681d20bbacb69517d2d2c875aa929eb9e
- https://github.com/frappe/erpnext/commit/f43af6624610e874e61ad3faf8701e5e6be6271a
- https://github.com/frappe/erpnext/pull/55721
- https://github.com/frappe/erpnext/releases/tag/v15.116.0
- https://github.com/frappe/erpnext/releases/tag/v16.23.0
- https://github.com/frappe/erpnext/security/advisories/GHSA-x35x-4mvx-h959



