CVE-2026-13227

An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. This issue affects ERPNext: before 15.115.0, before 16.26.0.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-04 21:16

Updated : 2026-08-28 15:31


NVD link : CVE-2026-13227

Mitre link : CVE-2026-13227

CVE.ORG link : CVE-2026-13227


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization