Report: Latest: CVE-2026-44440 - ERPNext: Path Traversal Leading to Sensitive File Exposure

Report: Latest: CVE-2026-44440 - ERPNext: Path Traversal Leading to Sensitive File Exposure

CVE ID :CVE-2026-44440 Published : May 13, 2026, 10:16 p.m. | 1 hour, 33 minutes ago Description :ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability on an endpoint allows an authenticated adjacent attacker to read arbitrary files. This vulnerability is fixed in 15.101.1 and 16.10.0. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
May 13, 2026
Attack Vector: adjacent
Impact: Path Traversal