{"id":"CVE-2026-94495","published":"2026-09-21T19:17:21.427","lastModified":"2026-09-21T19:17:21.427","description":"jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to modify tenant system configuration. Attackers can rewrite or delete tenant-wide settings covering company identity, stock rules, approval behavior, and printing configuration through the systemConfig endpoint.","cvssScore":7.1,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://github.com/LinYuanyi1/cve-request-poc/blob/master/jshERP/poc-10-systemconfig-tamper.py","tags":[]},{"url":"https://github.com/jishenghua/jshERP","tags":[]},{"url":"https://github.com/jishenghua/jshERP/blob/v3.6/jshERP-boot/src/main/java/com/jsh/erp/controller/SystemConfigController.java#L93-L115","tags":[]},{"url":"https://www.vulncheck.com/advisories/jsherp-through-3.6-missing-authorization-via-systemconfig","tags":[]}],"exploitRefs":[{"url":"https://github.com/LinYuanyi1/cve-request-poc/blob/master/jshERP/poc-10-systemconfig-tamper.py","tags":[]},{"url":"https://github.com/jishenghua/jshERP","tags":[]},{"url":"https://github.com/jishenghua/jshERP/blob/v3.6/jshERP-boot/src/main/java/com/jsh/erp/controller/SystemConfigController.java#L93-L115","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows authenticated users to modify tenant system configurations, potentially leading to unauthorized changes in company identity, stock rules, approval behavior, and printing settings.","exploitability":"Exploitation requires authentication but no specific user privileges are needed beyond basic access, making it relatively easy for malicious insiders or compromised accounts.","blast_radius":"If exploited, the impact could be significant as it affects tenant-wide settings critical to business operations, potentially leading to operational disruptions and data integrity issues.","remediation":"Update jshERP to version 3.7 or later which addresses this vulnerability according to the vendor.","tags":["auth-bypass","config-mgmt","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:17:41.508Z"}}