Executive Summary

A critical vulnerability, CVE-2026-59507, with a CVSS score of 9.3, has been identified in the Priority ERP Portal Generator addon developed by Soft Solutions. This vulnerability impacts all versions without Priwall v3 and stems from the use of hard-coded credentials, exposure of sensitive information to unauthorized actors, and improper access control. The vulnerability allows for high confidentiality impact and low integrity impact, with a changed scope.

Technical Analysis

The vulnerability is classified under CWE-798 (Use of Hard-coded Credentials), CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), and CWE-284 (Improper Access Control). The attack vector is network-based, with low attack complexity and no privileges required. The vulnerability affects the Priority ERP Portal Generator addon to Priority ERP, specifically all versions without Priwall v3.

How It Gets Exploited

An unauthenticated remote attacker on the network can exploit this vulnerability. The attacker would send a crafted request to the vulnerable endpoint, taking advantage of the hard-coded credentials and improper access control. This could allow the attacker to access sensitive information and potentially gain unauthorized access to the system. The technical details of the exploitation involve the attacker leveraging the vulnerability to bypass security controls and access sensitive data.

Impact Assessment

The vulnerability affects all versions of the Priority ERP Portal Generator addon without Priwall v3. An attacker could achieve exposure of sensitive information, improper access control, and potentially use hard-coded credentials for unauthorized access. The CVSS score of 9.3 indicates a critical severity level, with a high confidentiality impact and low integrity impact.

Recommended Actions

To mitigate this vulnerability, security professionals should:
  • Update the Priority ERP Portal Generator addon to version with Priwall v3 or later.
  • Restrict network access to the vulnerable endpoint.
  • Implement additional security controls, such as monitoring and logging, to detect potential exploitation attempts.

Sources