Vulnerability DatabaseCVE-2026-107841

CVE-2026-107841: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-107841 is an incorrect authorization vulnerability in pacioli-guard, the document-layer consent gate component of the pacioli least-privilege governance library for ERPNext. The flaw allows an authenticated attacker with an API Key carrying Scope.require_consent to submit a caller-controlled document (e.g., a Sales Invoice) under a valid human-minted consent marker and then trigger unauthorized cancellation of a different, pre-existing submitted document — bypassing the marker's document/act binding, single-use spend enforcement, and denial audit logging. It affects pacioli-guard versions >= 0.9.6 and < 0.10.0 (the only published version in the affected range is 0.9.6). The vulnerability was discovered via an internal adversarial review on 2026-07-28 and publicly disclosed on 2026-10-09. It carries a CVSS v3.1 base score of 5.7 (Moderate) (Github Advisory, GitHub Security Advisory).

Technical details

The root cause is CWE-863 (Incorrect Authorization): the ride predicate in pacioli-guard's consent gate returned true for every nested Document.cancel() call, regardless of which act the enclosing consent marker authorized. Because ERPNext allows nested document writes to "ride" an enclosing act's consent, any Document.cancel() executed within a consented act bypassed consent_verdict — the function responsible for enforcing marker-to-act binding — resulting in cancellations with no marker, no act-binding check, no single-use spend, and no denial audit row. A concrete exploitation path exists via Sales Invoice.on_submit (sales_invoice.py:507), which calls process_asset_depreciation() unconditionally; the Sales Invoice Item.asset field is a plain writable Link supplied by the caller in the request body, allowing the attacker to steer cancellation to an arbitrary pre-existing submitted Asset Depreciation Schedule. A similar path exists through Unreconcile Payment.on_submit, which can reach gain_loss_je.cancel() on submitted Journal Entries (Github Advisory, GitHub Security Advisory).

Impact

Successful exploitation allows an authenticated attacker to cancel pre-existing submitted financial documents (such as Asset Depreciation Schedules or Journal Entries) without proper human consent or audit trail, reversing their ledger effects in ERPNext. This constitutes a high-integrity impact: financial records can be silently altered, spend controls circumvented, and consent audit logs left incomplete. Confidentiality and availability are not directly impacted. Only sites that have opted into consent gating with Scope.require_consent credentials are affected; principals without such a grant are not exposed (Github Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (Github Advisory). The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, as user interaction is required. The EPSS score is 0.0, reflecting very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires a low-privilege authenticated credential with Scope.require_consent and user interaction, limiting the attacker pool to insiders or compromised broker credentials.

Exploitation steps

  1. Obtain a credential: Acquire an API Key with Scope.require_consent permission on a pacioli-guard 0.9.6 deployment — either as a legitimate operator, a compromised broker credential, or an insider.
  2. Identify a target document: Enumerate pre-existing submitted documents (e.g., Asset Depreciation Schedules, Journal Entries) whose cancellation would reverse a desired ledger effect.
  3. Craft a malicious Sales Invoice request: Construct a Sales Invoice submission request body that populates the Sales Invoice Item.asset Link field with the name of the target Asset Depreciation Schedule (or use the Unreconcile Payment path to target Journal Entries).
  4. Submit under a valid consent marker: Include a legitimate human-minted X-Pacioli-Consent marker (authorized for submitting the Sales Invoice) in the request header and submit the document via the governed API endpoint.
  5. Trigger nested cancellation: The Sales Invoice.on_submit handler calls process_asset_depreciation(), which iterates item rows and calls Document.cancel() on the caller-named asset's depreciation schedule. The ride predicate returns true, bypassing consent_verdict and cancelling the target document with docstatus = 2 — no separate marker, act-binding check, or audit row is generated (Github Advisory, GitHub Security Advisory).

Indicators of compromise

  • Logs: Absence of a denial audit row in pacioli-guard's consent audit log for a Document.cancel() operation on a pre-existing submitted document; docstatus transitions to 2 on financial documents (Asset Depreciation Schedules, Journal Entries) without a corresponding consent marker record.
  • Application Behavior: Sales Invoice submissions referencing Sales Invoice Item.asset values pointing to Asset Depreciation Schedules not associated with the invoiced items; Unreconcile Payment submissions with child table entries referencing Journal Entries not generated by the current act.
  • ERPNext Audit Trail: Cancelled documents (Asset Depreciation Schedules, Journal Entries) with reversed ledger effects where no human-approved cancellation consent marker exists in the pacioli-guard custody log.
  • API Activity: Repeated API calls to governed submission endpoints from broker credentials, particularly those submitting Sales Invoices or Unreconcile Payments with unusual or unexpected asset/journal entry references in the request body (Github Advisory).

Mitigation and workarounds

Upgrade pacioli-guard to version 0.10.0, which fixes the ride predicate to discriminate on the enclosing act — a submit may no longer cascade into cancellation of a pre-existing named document without its own consent marker. Note that upgrading changes behavior: ERPNext flows where a submit cascades into a lifecycle cancel (asset sale, partial-quantity asset sale, credit note against an asset sale, Asset Repair capitalization, Asset Shift Allocation, Asset Value Adjustment, Unreconcile Payment) now require a separate consent marker for each cancel; the X-Pacioli-Consent header in 0.10.0 accepts multiple markers separated by whitespace or commas. As a temporary workaround on 0.9.6, remove require_consent from affected grants and rely on the credential-scoping floor alone, or restrict governed credentials so they cannot submit documents whose controllers cancel other documents (the known path is Sales Invoice with a populated item-row asset link). Neither workaround substitutes for upgrading (Github Advisory, Patch Release).

Community reactions

The vulnerability was discovered through an internal adversarial review by the pacioli project maintainer (john-broadway) and disclosed responsibly via GitHub's private vulnerability reporting process. The advisory notes that the prior code comment had asserted no such exploitation lever was known, but that assertion was written without a corresponding source sweep of the ERPNext/frappe codebase. No significant external researcher commentary, media coverage, or notable social media discussion has been identified beyond standard CVE aggregator postings (Github Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-108258MEDIUM6.9
  • Python logoPython
  • shiny
NoYesOct 09, 2026
CVE-2026-48484MEDIUM6.5
  • Python logoPython
  • pyload-ng
NoYesOct 09, 2026
GHSA-p3pr-8f3m-4qp8MEDIUM6.4
  • Python logoPython
  • pyload-ng
NoNoOct 09, 2026
CVE-2026-107841MEDIUM5.7
  • Python logoPython
  • pacioli-guard
NoYesOct 09, 2026
CVE-2026-75597MEDIUM5.3
  • Python logoPython
  • pyload-ng
NoYesOct 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management