Executive brief
The Priority Portal Generator is an add-on to Priority ERP that provides web-based access to enterprise resource planning data. An improper access control vulnerability allows attackers to bypass authentication or authorization controls, potentially gaining unauthorized access to sensitive financial and operational data stored in the ERP system.
Technical details
The vulnerability is an improper access control flaw in the Portal Generator addon to Priority ERP. The affected component fails to properly validate user permissions or authentication tokens, allowing attackers to access restricted resources without proper authorization. The vulnerability affects all versions of the Portal Generator addon that do not include Priwall v3 security updates. No information is available regarding patch availability or specific attack vectors at this time.
Affected products
- Soft Solutions Priority Portal Generator all versions without Priwall v3
Timeline
- 2026-08-13: disclosed