PT-2026-96208 · Jsherp · Jsherp

·

CVE-2026-94495

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions jshERP versions prior to 3.7
Description Authenticated users can modify tenant system configuration due to improper validation of user privileges in the updateSystemConfig() function within the SystemConfigService. This allows attackers to rewrite or delete tenant-wide settings, including company identity, stock rules, approval behavior, and printing configuration, via the 'systemConfig' endpoint.
Recommendations Update jshERP to version 3.7 or later. As a temporary mitigation, restrict access to the 'systemConfig' endpoint to only highly privileged administrators.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94495

Affected Products

Jsherp