CVE-2026-94501: jshERP through 3.6 Privilege Escalation via userBusiness CRUD

Published Sep 21, 2026
·
Updated

jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without privilege checks. Attackers can manipulate user-role mappings and access controls to escalate privileges, strip access from other accounts, or modify role-function relationships for any user in the tenant.

Affected Software

1 affected component
jshERP<=3.6

Event History

Sep 21, 2026
CVE Published
via MITRE·06:16 PM
Data Sourced
via MITRE·06:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated jshERP user can exploit the vulnerable userBusiness CRUD endpoints. The provided data does not indicate that a specific role or elevated privilege is required.

2

What can an attacker do after exploiting the authorization bypass?

An attacker can create, modify, or delete authorization-relation rows without privilege checks. This can be used to alter user-role mappings and access controls, escalate privileges, remove other users' access, or change role-function relationships for users in the same tenant.

3

Are unauthenticated deployments exposed?

The issue requires authentication, so an unauthenticated remote attacker cannot exploit it directly based on the provided information. Any account with access to the affected endpoints may present a privilege-escalation risk.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203