Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3hj7-6vmj-h8v4 | pacioli: A submit consent marker licensed cancellation of caller-named pre-existing documents |
Fri, 09 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Oct 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pacioli provides least-privilege governance and a governed agent broker for ERPNext. From version 0.9.6 until version 0.10.0, the pacioli-guard document-layer consent gate allows nested cancellation operations to ride any consent established by an enclosing governed act without checking whether the marker authorizes cancellation. A credential with API Key Scope.require_consent can submit a caller-controlled Sales Invoice or other supported document under a valid human-minted submit marker and reach Document.cancel() for a different pre-existing submitted document, bypassing the marker's document and act binding, single-use spend, and denial audit. The unauthorized cancellation can reverse the target document's ledger effect; principals without a consent-gated grant are not affected. This issue is fixed in version 0.10.0. | |
| Title | pacioli: A submit consent marker licensed cancellation of caller-named pre-existing documents | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T18:41:50.092Z
Reserved: 2026-10-08T22:34:49.290Z
Link: CVE-2026-107841
Updated: 2026-10-09T18:41:45.881Z
Status : Received
Published: 2026-10-09T18:17:06.110
Modified: 2026-10-09T19:16:41.900
Link: CVE-2026-107841
No data.
OpenCVE Enrichment
Updated: 2026-10-09T19:30:11Z
-
CWE-863
Incorrect Authorization
Github GHSA