OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-94495

HIGH · CVSS 7.1 EPSS 0.44% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

jshERP versions up to 3.6 are vulnerable due to inadequate user privilege validation in the SystemConfigService.updateSystemConfig function, enabling authenticated users to alter critical tenant-wide settings. This flaw allows attackers to manipulate configurations related to company identity, stock rules, approval processes, and printing settings, potentially leading to significant operational disruptions. Organizations utilizing jshERP should prioritize patching this vulnerability to safeguard their system configurations and maintain data integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94495
Severity
HIGH
CVSS
7.1
EPSS
0.44%

Original NVD Description

jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to modify tenant system configuration. Attackers can rewrite or delete tenant-wide settings covering company identity, stock rules, approval behavior, and printing configuration through the systemConfig endpoint.