Description
A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component Financial Receipt Update Handler. Performing a manipulation results in improper authorization. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-10-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Improper Authorization leading to unauthorized manipulation of financial receipt data
Action: Patch
AI Analysis

Impact

The vulnerability is a flaw in the updateAccountHeadAndDetail function of the jshERP Financial Receipt Update Handler. It allows an attacker to perform actions without proper authorization, enabling unauthorized access to or modification of financial receipt records. The weakness aligns with improper privilege elevation and authorization failures.

Affected Systems

The affected product is jishenghua jshERP, versions up to 3.5. The specific source file is AccountHeadService.java located in the jshERP‑boot module. No version zero‑day patches are currently available from the vendor, and the project has not yet responded with a fix.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact. An exploit has been released to the public; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack can be initiated remotely when an affected endpoint is reachable, and success would allow an attacker to bypass authorization controls to manipulate financial data.

Generated by OpenCVE AI on October 6, 2026 at 04:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any official update or patch as soon as a vendor release is available
  • Restrict the Update AccountHeadAndDetail endpoint to authorized roles or disable it if not required
  • Deploy web application firewall rules to block suspicious requests targeting the vulnerable function

Generated by OpenCVE AI on October 6, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component Financial Receipt Update Handler. Performing a manipulation results in improper authorization. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Title jishenghua jshERP Financial Receipt Update AccountHeadService.java updateAccountHeadAndDetail improper authorization
First Time appeared Jishenghua
Jishenghua jsherp
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:jishenghua:jsherp:*:*:*:*:*:*:*:*
Vendors & Products Jishenghua
Jishenghua jsherp
References
Metrics cvssV2_0

{'score': 5.5, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 5.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Jishenghua Jsherp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-06T03:30:13.220Z

Reserved: 2026-10-05T16:27:00.107Z

Link: CVE-2026-105621

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-06T04:18:05.360

Modified: 2026-10-06T04:18:05.533

Link: CVE-2026-105621

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T04:30:19Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-285

    Improper Authorization