Executive brief
The Portal Generator addon to Priority ERP contains hard-coded credentials and improper access controls that could allow unauthorized users to gain sensitive information access. An attacker exploiting this vulnerability could bypass authentication and access confidential business data stored in the ERP system, potentially compromising customer data, financial records, and operational information.
Technical details
The Portal Generator addon to Priority ERP contains hard-coded credentials embedded in the application code or configuration files, combined with improper access control mechanisms. This allows an unauthenticated network attacker to discover and use these credentials to bypass authentication controls and directly access sensitive business information. The vulnerability affects all versions of the addon that do not include Priwall v3 security updates. Exploitation requires only network connectivity to the Portal Generator interface; no user interaction or prior authentication is needed. An attacker can leverage this to access confidential ERP data including customer records, financial transactions, and operational details. The fix is to upgrade to Portal Generator with Priwall v3 or apply equivalent security patches.
Affected products
- Soft Solutions Priority Portal Generator All versions without Priwall v3
- Soft Solutions Priority ERP All versions without Priwall v3
Timeline
- 2026-08-13: disclosed