CVE-2026-94501 Details
Description
jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without privilege checks. Attackers can manipulate user-role mappings and access controls to escalate privileges, strip access from other accounts, or modify role-function relationships for any user in the tenant.
An authorization bypass vulnerability has been identified in jshERP versions through 3.6. This vulnerability exists in the userBusiness CRUD endpoints, allowing authenticated users to create, modify, or delete authorization-related rows without proper privilege checks. As a result, attackers can manipulate user-role mappings and access controls, potentially escalating privileges, removing access from other accounts, or altering role-function relationships for any user within the tenant.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 21, 2026CISA-ADP
Assessed Sep 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| jshERP | <= 3.6 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 21, 2026 | New CVE Received | [email protected] |
| Sep 21, 2026 | CVE Modified | CISA-ADP |
Volerion