Junglewise Threat Intelligence

CVE-2026-59501: Soft Solutions Priority Portal Generator improper access control

CVE-2026-59501 · Severity: high · CVSS 8.2 · Published 2026-08-13

Technologies: Soft Solutions Priority Portal Generator. Vendors: Soft Solutions.

Executive brief

The Priority Portal Generator is an add-on to Priority ERP that provides web-based access to enterprise resource planning data. An improper access control vulnerability allows attackers to bypass authentication or authorization controls, potentially gaining unauthorized access to sensitive financial and operational data stored in the ERP system.

Technical details

The vulnerability is an improper access control flaw in the Portal Generator addon to Priority ERP. The affected component fails to properly validate user permissions or authentication tokens, allowing attackers to access restricted resources without proper authorization. The vulnerability affects all versions of the Portal Generator addon that do not include Priwall v3 security updates. No information is available regarding patch availability or specific attack vectors at this time.

Affected products

  • Soft Solutions Priority Portal Generator all versions without Priwall v3

Timeline

  • 2026-08-13: disclosed

References

Related threats