Executive brief
Priority Portal Generator is an addon for Priority ERP, an enterprise resource planning system used by organizations to manage business operations. This vulnerability allows unauthorized actors to access sensitive personal information stored within the system. The exposure could lead to customer data breaches, regulatory compliance violations, and reputational damage.
Technical details
The vulnerability involves exposure of sensitive personal information to unauthorized actors in the Priority Portal Generator addon to Priority ERP. The vulnerability affects all versions that do not include Priwall v3, which appears to be the security remediation. The attack vector and specific root cause are not detailed in the advisory, but the critical severity and high CVSS score (9.1) suggest network-accessible exposure with minimal authentication requirements. Organizations using the addon without Priwall v3 should upgrade immediately to versions that include Priwall v3 protection.
Affected products
- Soft Solutions Priority Portal Generator
Timeline
- 2026-08-13: disclosed