Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107841— pacioli: A submit consent marker licensed cancellation of caller-named pre-existing documents

Quick assessment

Affected
john-broadway pacioli
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Pacioli 为 ERPNext 提供了最小权限治理机制以及一个受控的代理中间件。在 0.9.6 版本至 0.10.0 版本期间,pacioli-guard 的文档层同意门控机制存在一个安全缺陷:允许嵌套的取消操作绕过对包含它的受控操作所建立的同意检查,而未验证该标记(marker)是否授权了取消行为。 拥有 凭据的攻击者,可以在一个有效的、由人类签发的提交标记(submit marker)下,提交一个由调用者控制的“销售发票”(Sales Invoice)或其他支持的文档,从而对另一个已预先存在且已提交的文档调

CVSS 5.7 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
john-broadway pacioli >= 0.9.6, < 0.10.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107841

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
pacioli: A submit consent marker licensed cancellation of caller-named pre-existing documents
Source: CVE Program / CVE List V5
Vulnerability Description
pacioli provides least-privilege governance and a governed agent broker for ERPNext. From version 0.9.6 until version 0.10.0, the pacioli-guard document-layer consent gate allows nested cancellation operations to ride any consent established by an enclosing governed act without checking whether the marker authorizes cancellation. A credential with API Key Scope.require_consent can submit a caller-controlled Sales Invoice or other supported document under a valid human-minted submit marker and reach Document.cancel() for a different pre-existing submitted document, bypassing the marker's document and act binding, single-use spend, and denial audit. The unauthorized cancellation can reverse the target document's ledger effect; principals without a consent-gated grant are not affected. This issue is fixed in version 0.10.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
john-broadway pacioli >= 0.9.6, < 0.10.0 -

II. Public POCs for CVE-2026-107841

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107841

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-107841 (1)

Other References for CVE-2026-107841 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-107841

No comments yet


Leave a comment