Executive brief
Priority Portal Generator is an addon for Priority ERP that enables external user access to enterprise resource planning functionality. A vulnerability in this addon exposes sensitive information to unauthorized actors, potentially compromising customer data and business operations. The issue affects all versions prior to the implementation of Priwall v3 security controls.
Technical details
This vulnerability involves exposure of sensitive information to an unauthorized actor in the Priority Portal Generator addon for Priority ERP. The affected component is the addon itself in all versions that do not include Priwall v3. The vulnerability appears to be accessible over the network as a remote information disclosure issue. An attacker can access sensitive data that should be restricted, though the specific preconditions (authentication requirements, network accessibility) and exact nature of exposed data are not detailed in the available advisory references.
Affected products
- Soft Solutions Priority ERP Portal Generator addon all versions without Priwall v3
Timeline
- 2026-08-13: disclosed