Junglewise Threat Intelligence

CVE-2026-94501: jshERP authorization bypass in userBusiness CRUD

CVE-2026-94501 · Severity: high · CVSS 8.8 · Published 2026-09-21

Technologies: Jishenghua jshERP. Vendors: Jishenghua.

Executive brief

jshERP is an open-source ERP system for small and medium enterprises that manages inventory, sales, purchases, and finances. This vulnerability allows authenticated users to manipulate user-role assignments and access controls without proper authorization, enabling privilege escalation, account lockout, or unauthorized access to sensitive business functions.

Technical details

A missing authorization check (CWE-862) in the userBusiness CRUD endpoints (/userBusiness/add, /userBusiness/update, /userBusiness/delete) allows any authenticated user to create, modify, or delete rows in the jsh_user_business authorization-relation table. An attacker with valid credentials can tamper with user-role mappings and role-function relationships, escalating privileges or revoking access from other accounts within the tenant.

Affected products

  • jishenghua jshERP through 3.6

Timeline

  • 2026-09-21: disclosed

References

Related threats