天下漏洞,尽知其名
MEDIUM

CVE-2026-107841 pacioli 权限绕过漏洞

影响攻击者可绕过授权取消已提交单据,逆转账务影响

AI 研判

pacioli 是面向 ERPNext 的最小权限治理与受管代理组件。其 pacioli-guard 文档层同意门控在 0.9.6 至 0.10.0 之前版本中,允许嵌套取消操作借用外层受管操作已建立的同意标记,而不校验该标记是否授权取消。持有 API Key Scope.require_consent 的凭证可借此绕过标记的文档与操作绑定、单次使用限制及拒绝审计。

影响范围

pacioli

pacioli 0.9.6 起至 0.10.0 之前的版本受影响,0.10.0 已修复。

漏洞详情

漏洞类型为权限绕过(授权校验缺失)。成因是同意门控对嵌套取消操作未做标记与操作的绑定校验,导致外层提交标记被复用于取消另一份已存在的已提交单据。利用方式是攻击者以具备 require_consent 范围的凭证,在有效人工签发的提交标记下提交受控单据,进而调用 Document.cancel() 取消目标单据。

利用条件与风险

利用前提是攻击者持有带 API Key Scope.require_consent 的凭证;成功后可未经授权取消已提交单据并逆转其账务影响,但未获同意门控授权的凭证不受影响。

修复建议

升级至 pacioli 0.10.0 或更高版本以修复该问题;暂无公开的临时缓解措施信息。

原始情报

pacioli provides least-privilege governance and a governed agent broker for ERPNext. From version 0.9.6 until version 0.10.0, the pacioli-guard document-layer consent gate allows nested cancellation operations to ride any consent established by an enclosing governed act without checking whether the marker authorizes cancellation. A credential with API Key Scope.require_consent can submit a caller-controlled Sales Invoice or other supported document under a valid human-minted submit marker and reach Document.cancel() for a different pre-existing submitted document, bypassing the marker’s document and act binding, single-use spend, and denial audit. The unauthorized cancellation can reverse the target document’s ledger effect; principals without a consent-gated grant are not affected. This issue is fixed in version 0.10.0.