CVE-2026-94497

Summary

jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and delete other users' business objects by submitting direct object identifiers without authorization checks.

Affected Software

VendorProductVersion RangeStatus
jishenghuajshERP0 <= 3.6affected

Weaknesses

  • CWE-639: CWE-639 Authorization Bypass Through User-Controlled Key

References