CVE-2026-94497: jshERP through 3.6 Unauthorized Access via by-id Endpoints
Published Sep 21, 2026
·Updated
jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and delete other users' business objects by submitting direct object identifiers without authorization checks.
Affected Software
1 affected component
jshERP<=3.6
Event History
Sep 21, 2026
CVE Published
via MITRE·06:16 PM
Data Sourced
via MITRE·06:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
An attacker needs an authenticated jshERP account with low privileges. No user interaction is required.
2
Which releases are known to be affected?
jshERP versions through 3.6 are affected.