Description
: Observable Discrepancy vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).

This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.
Published: 2026-08-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Observable Discrepancy in the Priority Portal Generator addon to Priority ERP allows external observers to detect unintended differences in portal responses. This behavior, classified as CWE‑203, can reveal system or configuration details and result in information disclosure. Although it does not facilitate direct code execution, the ability to gather reconnaissance data about the underlying infrastructure can support subsequent attacks.

Affected Systems

All releases of the Priority Portal Generator addon to Priority ERP distributed by Soft Solutions that do not include Priwall v3 are affected. These add‑ons are typically deployed as part of the Priority ERP suite and may be reachable from the public internet or from internal networks if not properly isolated.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that the vulnerability can be triggered by sending requests to the portal’s publicly exposed endpoints when the addon is reachable from outside the secure network. Attackers could use the observed differences to gather reconnaissance data, but the lack of a public exploit and low EPSS mitigate immediate risk. The recommended mitigation involves restricting internet exposure or upgrading to Modern Priority Portals, which removes the observable discrepancy.

Generated by OpenCVE AI on August 24, 2026 at 22:40 UTC.

Remediation

Vendor Solution

Either do not expose your Priority infrastructure to the internet, or use Modern Priority Portals by Priority Software


OpenCVE Recommended Actions

  • Restrict public access to the Portal Generator add‑on by deploying a firewall or reverse‑proxy rule that blocks external traffic while permitting legitimate internal use.
  • Confirm the add‑on is not exposed to the public internet; configure network segmentation or NAT rules to enforce internal‑only access.
  • Upgrade to the Modern Priority Portals provided by Priority Software, which eliminates the observable discrepancy and resolves the vulnerability.

Generated by OpenCVE AI on August 24, 2026 at 22:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description CWE-203: Observable Discrepancy : Observable Discrepancy vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

Thu, 13 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Priority
Priority portal Generator Addon To Priority Erp (developed By Soft Solutions)
Vendors & Products Priority
Priority portal Generator Addon To Priority Erp (developed By Soft Solutions)

Thu, 13 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Description CWE-203: Observable Discrepancy
Title Priority - CWE-203: Observable Discrepancy
Weaknesses CWE-203
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Priority Portal Generator Addon To Priority Erp (developed By Soft Solutions)
cve-icon MITRE

Status: PUBLISHED

Assigner: INCD

Published:

Updated: 2026-08-24T16:16:20.663Z

Reserved: 2026-07-05T09:17:04.753Z

Link: CVE-2026-59502

cve-icon Vulnrichment

Updated: 2026-08-13T14:31:31.264Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T10:17:15.257

Modified: 2026-08-28T16:08:44.147

Link: CVE-2026-59502

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:45:03Z

Weaknesses