OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-94412

HIGH · CVSS 8.8 EPSS 0.55% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The vulnerability in jshERP versions up to 3.6 allows authenticated users to exploit the POST /user/resetPwd endpoint, enabling them to reset any user's password, including those of administrators, by submitting a request with an arbitrary user ID. This authorization bypass poses a significant risk of unauthorized access to sensitive accounts and data. Organizations using jshERP should prioritize immediate remediation to protect against potential account takeovers.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94412
Severity
HIGH
CVSS
8.8
EPSS
0.55%

Original NVD Description

jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to reset any other user's password. Attackers can submit a request with an arbitrary target user ID to reset that account's password to a known default value, enabling unauthorized access to other user accounts including administrators.