Executive brief
The Priority Portal Generator is an add-on module for Priority ERP that enables external users to access and interact with enterprise resource data. A missing authentication vulnerability allows attackers to access critical functions without proper credentials, potentially exposing sensitive business data and enabling unauthorized modifications to ERP records.
Technical details
This is an authentication bypass vulnerability in the Priority Portal Generator addon to Priority ERP. The vulnerability affects all versions of the addon without Priwall v3 protection, allowing unauthenticated access to critical functions. The flaw permits attackers to invoke protected operations without providing valid credentials or session tokens, potentially leading to unauthorized data access and modification. The issue is network-reachable and requires no user interaction or prior authentication. Patches are available through Priwall v3.
Affected products
- Soft Solutions Priority ERP Portal Generator All versions without Priwall v3
Timeline
- 2026-08-13: disclosed