{"apiVersion":"1.0","identifier":"CVE-2026-65822","description":"ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/report/inactive_customers/inactive_customers.py accepts an unvalidated doctype filter and interpolates it into raw SQL in get_sales_details and get_last_sales_amt, allowing an authenticated user to extract sensitive information and manipulate database queries. This issue is fixed in versions 15.116.0 and 16.23.0.","publishedAt":"2026-08-17T21:16:46","lastModifiedAt":"2026-08-18T13:17:27","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-65822","cvssScore":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L","epssProbability":0.00264,"riskScore":0.78,"affectedProduct":"ERPNext","affectedVersions":"<15.116.0,<16.23.0","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-65822","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-65822","en":"https://www.redsauce.net/en/cves/CVE-2026-65822","fr":"https://www.redsauce.net/fr/cves/CVE-2026-65822","pt":"https://www.redsauce.net/pt/cves/CVE-2026-65822","de":"https://www.redsauce.net/de/cves/CVE-2026-65822","sk":"https://www.redsauce.net/sk/cves/CVE-2026-65822","el":"https://www.redsauce.net/el/cves/CVE-2026-65822"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-65822"}}