Description
: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).

This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.
Published: 2026-08-13
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper Access Control in the Priority Portal Generator add‑on to Priority ERP (developed by Soft Solutions) allows an attacker to bypass authorization checks and access protected resources. All versions without Priwall v3 are vulnerable. This flaw can lead to unauthorized data exposure or modification, compromising the confidentiality and integrity of ERP data.

Affected Systems

Affected systems include the Priority ERP Portal Generator add‑on by Soft Solutions, all versions lacking Priwall v3, which is part of the Priority ERP platform. Administrators and users are impacted if the standard configuration exposes the portal to the internet.

Risk and Exploitability

The CVSS score of 8.2 marks this as high severity. The EPSS score is 0.00244, indicating a low probability of exploitation. KEV lists it as not included. The likely attack vector is remote over the internet, as the recommendation explicitly warns against exposing the infrastructure. An attacker can exploit the flaw if the portal is accessible from outside, potentially bypassing authentication or authorization controls.

Generated by OpenCVE AI on August 24, 2026 at 22:41 UTC.

Remediation

Vendor Solution

Either do not expose your Priority infrastructure to the internet, or use Modern Priority Portals by Priority Software


OpenCVE Recommended Actions

  • Restrict exposure of the Priority infrastructure to the internet.
  • Deploy Modern Priority Portals by Priority Software if internet access is required.
  • Remove or disable the Portal Generator add‑on when it is not needed to reduce the attack surface.

Generated by OpenCVE AI on August 24, 2026 at 22:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description CWE-284: Improper Access Control : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

Thu, 13 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Priority
Priority portal Generator Addon To Priority Erp (developed By Soft Solutions)
Vendors & Products Priority
Priority portal Generator Addon To Priority Erp (developed By Soft Solutions)

Thu, 13 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Description CWE-284: Improper Access Control
Title Priority – CWE-284: Improper Access Control
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Priority Portal Generator Addon To Priority Erp (developed By Soft Solutions)
cve-icon MITRE

Status: PUBLISHED

Assigner: INCD

Published:

Updated: 2026-08-24T16:15:21.950Z

Reserved: 2026-07-05T09:17:04.753Z

Link: CVE-2026-59501

cve-icon Vulnrichment

Updated: 2026-08-13T14:30:07.369Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T10:17:15.140

Modified: 2026-08-28T16:08:44.147

Link: CVE-2026-59501

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:45:03Z

Weaknesses