Junglewise Threat Intelligence

CVE-2026-94412: jshERP authorization bypass in password reset

CVE-2026-94412 · Severity: high · CVSS 8.8 · Published 2026-09-21

Technologies: Jishenghua jshERP. Vendors: Jishenghua.

Executive brief

jshERP is an open-source ERP system used by small and medium-sized businesses for inventory, sales, purchasing, and financial management. An authenticated user can reset any other user's password, including administrators, through the password reset endpoint, enabling complete account takeover and unauthorized access to sensitive business data.

Technical details

The POST /user/resetPwd endpoint fails to properly validate authorization, allowing authenticated low-privilege users to reset passwords for arbitrary user accounts within the same tenant via CWE-862 (missing authorization). An attacker with valid credentials can submit requests with a target user ID to change that account's password to a known value, gaining full access including to tenant administrator accounts. The vulnerability affects versions through 3.6 and requires valid authentication but no additional user interaction.

Affected products

  • jishenghua jshERP through 3.6

Timeline

  • 2026-09-21: disclosed

References

Related threats