Description
: Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).

This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.
Published: 2026-08-13
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper authentication vulnerability identified as CWE‑287 that allows bypassing the Portal Generator add‑on’s login checks in Priority ERP. An attacker who gains access can impersonate legitimate users, read or modify ERP data, and perform unauthorized actions. The impact is a loss of confidentiality, integrity, and possibly availability of the portal’s data.

Affected Systems

All installations of Priority ERP that use the Portal Generator add‑on and lack Priwall v3 are vulnerable. This includes versions developed by Soft Solutions that have not incorporated the Priwall v3 update.

Risk and Exploitability

The CVSS score of 10 marks this issue as critical. The EPSS score of < 1% suggests that exploitation is unlikely, but the advisory’s recommendation to keep the infrastructure out of reach of the Internet indicates that remote exploitation over public networks is the intended attack vector. An adversary could exploit the authentication bypass remotely to obtain full portal access.

Generated by OpenCVE AI on August 24, 2026 at 23:08 UTC.

Remediation

Vendor Solution

Either do not expose your Priority infrastructure to the internet, or use Modern Priority Portals by Priority Software


OpenCVE Recommended Actions

  • Restrict inbound traffic so the Priority portal is not reachable from the Internet.
  • Upgrade to the Modern Priority Portals solution from Priority Software, which removes the outdated authentication logic.
  • Configure the portal to require strong authentication policies, such as MFA, and monitor login logs for anomalous access attempts.

Generated by OpenCVE AI on August 24, 2026 at 23:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description CWE-287: Improper Authentication : Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

Thu, 13 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Priority
Priority portal Generator Addon To Priority Erp (developed By Soft Solutions)
Vendors & Products Priority
Priority portal Generator Addon To Priority Erp (developed By Soft Solutions)

Thu, 13 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description CWE-287: Improper Authentication
Title Priority - CWE-287: Improper Authentication
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Priority Portal Generator Addon To Priority Erp (developed By Soft Solutions)
cve-icon MITRE

Status: PUBLISHED

Assigner: INCD

Published:

Updated: 2026-08-24T16:14:32.388Z

Reserved: 2026-07-05T09:17:04.753Z

Link: CVE-2026-59500

cve-icon Vulnrichment

Updated: 2026-08-13T14:29:48.792Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T10:17:15.017

Modified: 2026-08-28T16:08:44.147

Link: CVE-2026-59500

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T23:15:04Z

Weaknesses