Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pacioli provides least-privilege governance and a governed agent broker for ERPNext. From version 0.9.6 until version 0.10.0, the pacioli-guard document-layer consent gate allows nested cancellation operations to ride any consent established by an enclosing governed act without checking whether the marker authorizes cancellation. A credential with API Key Scope.require_consent can submit a caller-controlled Sales Invoice or other supported document under a valid human-minted submit marker and reach Document.cancel() for a different pre-existing submitted document, bypassing the marker's document and act binding, single-use spend, and denial audit. The unauthorized cancellation can reverse the target document's ledger effect; principals without a consent-gated grant are not affected. This issue is fixed in version 0.10.0. | |
| Title | pacioli: A submit consent marker licensed cancellation of caller-named pre-existing documents | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T18:41:50.092Z
Reserved: 2026-10-08T22:34:49.290Z
Link: CVE-2026-107841
No data.
Status : Received
Published: 2026-10-09T18:17:06.110
Modified: 2026-10-09T18:17:06.110
Link: CVE-2026-107841
No data.
OpenCVE Enrichment
No data.