CVE-2026-94412
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
21/09/2026
Last modified:
22/09/2026
Description
jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to reset any other user's password. Attackers can submit a request with an arbitrary target user ID to reset that account's password to a known default value, enabling unauthorized access to other user accounts including administrators.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/LinYuanyi1/cve-request-poc/blob/master/jshERP/poc-02-user-resetpwd-account-takeover.py
- https://github.com/jishenghua/jshERP
- https://github.com/jishenghua/jshERP/blob/v3.6/jshERP-boot/src/main/java/com/jsh/erp/controller/UserController.java#L230-L244
- https://www.vulncheck.com/advisories/jsherp-through-3.6-authorization-bypass-via-resetpwd


