{"id":"CVE-2026-94501","published":"2026-09-21T19:17:21.910","lastModified":"2026-09-21T19:17:21.910","description":"jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without privilege checks. Attackers can manipulate user-role mappings and access controls to escalate privileges, strip access from other accounts, or modify role-function relationships for any user in the tenant.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://github.com/LinYuanyi1/cve-request-poc/blob/master/jshERP/poc-07-userbusiness-authorization-delete.py","tags":[]},{"url":"https://github.com/jishenghua/jshERP","tags":[]},{"url":"https://github.com/jishenghua/jshERP/blob/v3.6/jshERP-boot/src/main/java/com/jsh/erp/controller/UserBusinessController.java#L50-L80","tags":[]},{"url":"https://www.vulncheck.com/advisories/jsherp-through-3.6-privilege-escalation-via-userbusiness-crud","tags":[]}],"exploitRefs":[{"url":"https://github.com/LinYuanyi1/cve-request-poc/blob/master/jshERP/poc-07-userbusiness-authorization-delete.py","tags":[]},{"url":"https://github.com/jishenghua/jshERP","tags":[]},{"url":"https://github.com/jishenghua/jshERP/blob/v3.6/jshERP-boot/src/main/java/com/jsh/erp/controller/UserBusinessController.java#L50-L80","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows authenticated users to bypass authorization checks in jshERP through 3.6, enabling them to manipulate user-role mappings and escalate privileges.","exploitability":"Exploitation requires authentication but no specific technical skills; preconditions include access to the affected software version.","blast_radius":"If exploited, attackers can strip access from other accounts or modify role-function relationships, significantly impacting system security and integrity.","remediation":"Update to the latest version of jshERP, which should address this vulnerability.","tags":["auth-bypass","web","priv-escalation"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:05:35.610Z"}}