CVE-2026-94494

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
21/09/2026
Last modified:
22/09/2026

Description

jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint. Attackers can iterate the primary key to enumerate and access sensitive tenant data including login names, validity dates, user quotas, and enabled state across all platform tenants.