ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/report/inactive_customers/inactive_customers.py accepts an unvalidated doctype filter and interpolates it into raw SQL in get_sales_details and get_last_sales_amt, allowing an authenticated user to extract sensitive information and manipulate database queries. This issue is fixed in versions 15.116.0 and 16.23.0.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-89"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65822.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "15.116.0"
},
{
"introduced": "16.0.0"
},
{
"fixed": "16.23.0"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}