Junglewise Threat Intelligence

CVE-2026-94414: jshERP authorization bypass in userBusiness endpoint

CVE-2026-94414 · Severity: medium · CVSS 5.4 · Published 2026-09-21

Executive brief

jshERP is an open-source ERP system used by small and mid-size businesses for inventory, sales, purchasing, and financial management. An authenticated user can modify role-based button permissions for any role without proper authorization checks, potentially allowing them to grant themselves or others elevated access to sensitive features like financial or inventory controls.

Technical details

The POST /userBusiness/updateBtnStr endpoint is missing authorization validation (CWE-862), allowing any authenticated user to supply arbitrary roleId and btnStr parameters to overwrite button-permission configurations for any role. The vulnerability requires valid authentication credentials but no elevated privilege, and the attacker gains the ability to reconfigure UI/button access controls for any role in the tenant.

Affected products

  • jshERP Project jshERP through 3.6

Timeline

  • 2026-09-21: disclosed

References