Description
: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions)..

This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions).: All versions without Priwall v3.
Published: 2026-08-13
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a CWE‑200 information disclosure in the Priority Portal Generator add‑on for Priority ERP. An unauthorized actor can access confidential data that is inadvertently exposed by the add‑on, leading to a breach of confidentiality. All versions lacking Priwall v3 are affected. The advisory does not indicate additional privilege escalation, denial of service, or data integrity issues, so the primary impact is the loss of data confidentiality.

Affected Systems

The affected software is the Portal Generator add‑on for Priority ERP, developed by Soft Solutions. No specific versions are enumerated in the advisory, implying that all current releases employing the add‑on may be vulnerable.

Risk and Exploitability

The CVSS score of 8.6 signals a high‑severity issue. The EPSS score is less than 1%, indicating a very low but non‑zero exploitation probability. The vulnerability is not listed in CISA KEV. The likely attack vector is remote, enabled by exposing the Priority ERP infrastructure to the internet. If the system is accessible from outside the corporate network, an attacker could exploit the information disclosure without additional credentials. The CNA’s guidance notes that disabling internet exposure or migrating to Modern Priority Portals mitigates the risk.

Generated by OpenCVE AI on August 24, 2026 at 22:15 UTC.

Remediation

Vendor Solution

Either do not expose your Priority infrastructure to the internet, or use Modern Priority Portals by Priority Software.


OpenCVE Recommended Actions

  • Restrict Priority ERP infrastructure from internet exposure through network segmentation or firewall rules
  • Upgrade to or replace the Portal Generator add‑on with Modern Priority Portals provided by Priority Software
  • Disable or remove the Portal Generator add‑on if it is not essential, and review exposed endpoints to ensure no sensitive data is displayed

Generated by OpenCVE AI on August 24, 2026 at 22:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description CWE-200: Exposure of Sensitive Information to an Unauthorized Actor : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).. This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions).: All versions without Priwall v3.

Fri, 14 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Priority
Priority portal Generator Addon To Priority Erp (developed By Soft Solutions).
Vendors & Products Priority
Priority portal Generator Addon To Priority Erp (developed By Soft Solutions).

Thu, 13 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Title Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Priority Portal Generator Addon To Priority Erp (developed By Soft Solutions).
cve-icon MITRE

Status: PUBLISHED

Assigner: INCD

Published:

Updated: 2026-08-24T16:13:10.372Z

Reserved: 2026-07-05T09:17:04.753Z

Link: CVE-2026-59499

cve-icon Vulnrichment

Updated: 2026-08-13T14:43:54.497Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T10:17:14.877

Modified: 2026-08-28T16:08:44.147

Link: CVE-2026-59499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:30:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor