Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and delete other users' business objects by submitting direct object identifiers without authorization checks. | |
| Title | jshERP through 3.6 Unauthorized Access via by-id Endpoints | |
| First Time appeared |
Jishenghua
Jishenghua jsherp |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:jishenghua:jsherp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jishenghua
Jishenghua jsherp |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-21T18:16:18.452Z
Reserved: 2026-09-21T17:52:02.192Z
Link: CVE-2026-94497
No data.
Status : Received
Published: 2026-09-21T19:17:21.743
Modified: 2026-09-21T19:17:21.743
Link: CVE-2026-94497
No data.
OpenCVE Enrichment
No data.
