CVE-2026-94494: jshERP through 3.6 Tenant Information Disclosure via GET /tenant/info

Published Sep 21, 2026
·
Updated

jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint. Attackers can iterate the primary key to enumerate and access sensitive tenant data including login names, validity dates, user quotas, and enabled state across all platform tenants.

Affected Software

1 affected component
jshERP<=3.6

Event History

Sep 21, 2026
CVE Published
via MITRE·06:16 PM
Data Sourced
via MITRE·06:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated jshERP user can exploit it. The attacker needs only low-privileged access and network reachability to the GET /tenant/info endpoint; no user interaction is required.

2

What information can be exposed?

An attacker can enumerate other tenants by iterating primary-key values and retrieve tenant records. Exposed fields include login names, validity dates, user quotas, and enabled-state information.

3

Are deployments affected by default?

The provided information identifies jshERP through version 3.6 as affected and does not describe any non-default feature or configuration prerequisite. The vulnerable endpoint is GET /tenant/info.

4

How can I determine whether exploitation may have occurred?

Review application or reverse-proxy logs for authenticated requests to GET /tenant/info, particularly repeated requests with sequential or varied primary-key values. Such patterns may indicate tenant enumeration attempts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203