Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-94497

HIGH NVD
CVSS Score 8.3
Severity HIGH
Published Sep 21, 2026
Vendor unknown

Description

jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and delete other users' business objects by submitting direct object identifiers without authorization checks.

References