Report: CVE-2026-44441 - ERPNext: Possible SSRF by any authenticated user - Analysis

Report: CVE-2026-44441 - ERPNext: Possible SSRF by any authenticated user - Analysis

CVE ID :CVE-2026-44441 Published : May 13, 2026, 10:16 p.m. | 1 hour, 33 minutes ago Description :ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user could send a crafted request to an endpoint, which would lead to the server making an HTTP call to a service of the user's choice. This vulnerability is fixed in 15.106.0 and 16.16.0. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
May 13, 2026