Vulnerabilities
Report: Latest: CVE-2026-44440 - ERPNext: Path Traversal Leading to Sensitive File Exposure
CVE ID :CVE-2026-44440 Published : May 13, 2026, 10:16 p.m. | 1 hour, 33 minutes ago Description :ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability on an endpoint allows an authenticated adjacent attacker to read arbitrary files. This vulnerability is fixed in 15.101.1 and 16.10.0. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
Attack Vector:
adjacent
Impact:
Path Traversal