CVE-2026-94496: CWE-862 Missing Authorization in jishenghua jshERP
jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify any role's data scope or delete roles. Attackers can exploit the /role/update and /role/delete endpoints to escalate privileges, change data visibility to all data, and access all business records in the tenant.
AI Analysis
Technical Summary
CVE-2026-94496 is a missing authorization vulnerability (CWE-862) in jshERP through version 3.6. The application fails to validate caller permissions on the /role/update and /role/delete endpoints, enabling authenticated users to escalate privileges by modifying roles' data scopes or deleting roles. This can lead to unauthorized access to all tenant business data.
Potential Impact
Exploitation of this vulnerability allows authenticated users to escalate their privileges by changing role permissions or deleting roles, resulting in unauthorized access to sensitive business records and potentially compromising the confidentiality and integrity of tenant data. The CVSS 3.1 score of 8.3 reflects a high severity with network attack vector, low attack complexity, and high impact on confidentiality and integrity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to role management endpoints to trusted administrators only and monitor for suspicious activity related to role modifications.
CVE-2026-94496: CWE-862 Missing Authorization in jishenghua jshERP
Description
jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify any role's data scope or delete roles. Attackers can exploit the /role/update and /role/delete endpoints to escalate privileges, change data visibility to all data, and access all business records in the tenant.
CVSS v3.1
Score 8.3high
Affected software
jishenghua
jshERP
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-94496 is a missing authorization vulnerability (CWE-862) in jshERP through version 3.6. The application fails to validate caller permissions on the /role/update and /role/delete endpoints, enabling authenticated users to escalate privileges by modifying roles' data scopes or deleting roles. This can lead to unauthorized access to all tenant business data.
Potential Impact
Exploitation of this vulnerability allows authenticated users to escalate their privileges by changing role permissions or deleting roles, resulting in unauthorized access to sensitive business records and potentially compromising the confidentiality and integrity of tenant data. The CVSS 3.1 score of 8.3 reflects a high severity with network attack vector, low attack complexity, and high impact on confidentiality and integrity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to role management endpoints to trusted administrators only and monitor for suspicious activity related to role modifications.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-21T17:52:01.686Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab1783255bf5e2cf54cd25d
Added to database: 09/21/2026, 18:32:18 UTC
Last enriched: 09/21/2026, 18:46:38 UTC
Last updated: 09/22/2026, 00:43:09 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.