Executive brief
Priority Portal Generator is an addon to Priority ERP that manages web-based access to enterprise resource planning data. A client-side security enforcement flaw allows attackers to bypass server-side security controls, potentially exposing sensitive business data and enabling unauthorized transactions in the ERP system.
Technical details
This vulnerability is a client-side enforcement bypass affecting the Portal Generator addon to Priority ERP. Security controls that should be enforced server-side are instead implemented only on the client, allowing an attacker to circumvent them by intercepting or modifying client-side logic. The vulnerability is network-accessible with no authentication required. An attacker can bypass access controls and potentially read, modify, or delete data within the Priority ERP system. The issue affects all versions prior to the Priwall v3 security update; systems running Priwall v3 or later are not vulnerable.
Affected products
- Soft Solutions Priority Portal Generator all versions prior to Priwall v3
Timeline
- 2026-08-13: disclosed