Junglewise Threat Intelligence

CVE-2026-59505: Soft Solutions Priority Portal Generator improper access control

CVE-2026-59505 · Severity: high · CVSS 8.6 · Published 2026-08-13

Vendors: Soft Solutions.

Executive brief

The Priority Portal Generator is an addon to the Priority ERP system that manages business processes and data. An access control vulnerability allows unauthorized users to bypass security controls and access sensitive business information or perform unauthorized actions within the system. Organizations using unpatched versions face exposure of critical operational and financial data.

Technical details

This improper access control vulnerability exists in the Portal Generator addon to Priority ERP. The vulnerability allows attackers to bypass authentication or authorization controls to gain unauthorized access to protected resources. The issue affects all versions of Portal Generator that do not include Priwall v3, which presumably contains the necessary security fixes. No network connectivity restrictions are mentioned, suggesting the vulnerability may be reachable remotely depending on deployment. Patching to a version that includes Priwall v3 is required to remediate the issue.

Affected products

  • Soft Solutions Portal Generator All versions without Priwall v3

Timeline

  • 2026-08-13: disclosed

References