CVE-2026-94497

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
21/09/2026
Last modified:
22/09/2026

Description

jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and delete other users' business objects by submitting direct object identifiers without authorization checks.