CVE-2026-94414: jshERP through 3.6 Missing Authorization via updateBtnStr

Published Sep 21, 2026
·
Updated

jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticated users to modify role button-permission definitions. Attackers can supply arbitrary roleId and btnStr parameters to overwrite button-permission configurations for any role in the tenant without privilege validation.

Affected Software

1 affected component
jshERP<=3.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade jshERP to a version that resolves this vulnerability.

    Fixed in 3.6
  2. Compensating control

    Restrict access to the POST /userBusiness/updateBtnStr endpoint (e.g., via network/WAF/ACL) so only authorized administrators/roles can call it, until the missing authorization is fixed.

Event History

Sep 21, 2026
CVE Published
via MITRE·06:16 PM
Data Sourced
via MITRE·06:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated jshERP user can exploit the affected endpoint. The attacker does not need elevated privileges because the endpoint does not validate authorization for the supplied role identifier.

2

What access is required to change another role's button permissions?

The attacker needs an authenticated session and the ability to send a POST request to /userBusiness/updateBtnStr. They can provide arbitrary roleId and btnStr values to overwrite button-permission definitions for roles in the tenant.

3

What is the practical impact of a successful exploit?

An attacker can alter button-level permissions assigned to roles, potentially granting or removing access to application functions for users holding those roles. The reported impact includes integrity and availability effects, but not confidentiality impact.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203