Junglewise Threat Intelligence

CVE-2026-59500: Soft Solutions Priority Portal Generator improper authentication

CVE-2026-59500 · Severity: critical · CVSS 10 · Published 2026-08-13

Technologies: Soft Solutions Priority Portal Generator. Vendors: Soft Solutions.

Executive brief

Priority Portal Generator is an addon to Priority ERP that enables external users to access enterprise resource planning functionality through a web portal. An improper authentication vulnerability allows attackers to bypass access controls and gain unauthorized access to the ERP system without valid credentials, potentially exposing sensitive business data and enabling malicious transactions.

Technical details

The Portal Generator addon to Priority ERP contains an improper authentication vulnerability that affects all versions not patched with Priwall v3. The vulnerability allows attackers to bypass authentication mechanisms and gain unauthorized access to the system. No network restrictions or user interaction is required for exploitation. An attacker can leverage this flaw to access sensitive ERP data, modify business records, or perform unauthorized transactions. The vulnerability is addressed through deployment of Priwall v3 security updates.

Affected products

  • Soft Solutions Priority Portal Generator All versions without Priwall v3

Timeline

  • 2026-08-13: disclosed

References

Related threats