Description
: Exposure of Sensitive Information to an Unauthorized Actor : Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).

This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.
Published: 2026-08-13
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Priority’s Portal Generator addon to Priority ERP, developed by Soft Solutions, allows an unauthorized actor to access sensitive and private personal data stored in the ERP system. This flaw is a classic information disclosure vulnerability, classified as CWE‑200, exposing confidential data and private personal information.

Affected Systems

Affected systems are installations of Priority ERP that use the Portal Generator addon, developed by Soft Solutions. The addon must be present; specific versions are not listed in the advisory, so all deployed instances of the portal generator are vulnerable unless configured otherwise.

Risk and Exploitability

The CVSS score of 9.1 indicates a critical severity. The EPSS score is 0.00303, indicating a very low but nonzero likelihood of exploitation, but the vulnerability is still considered likely to be exploited if the addon is reachable from the internet. According to the CNA, the attacker could retrieve sensitive data via the portal’s web interface, assuming no additional access controls are in place. The vulnerability is not listed in the CISA KEV catalog, however precautionary measures remain essential.

Generated by OpenCVE AI on August 24, 2026 at 22:14 UTC.

Remediation

Vendor Solution

Either do not expose your Priority infrastructure to the internet, or use Modern Priority Portals by Priority Software


OpenCVE Recommended Actions

  • Disable or block internet exposure of the Priority ERP environment, ensuring the portal generator addon is only accessible from trusted internal networks.
  • Upgrade to the Modern Priority Portals solution offered by Priority Software, which addresses the information disclosure flaw.
  • Apply strict access controls on the portal, restricting sensitive data exposure to authenticated and authorized users only.

Generated by OpenCVE AI on August 24, 2026 at 22:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor : Exposure of Sensitive Information to an Unauthorized Actor : Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

Thu, 13 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Priority
Priority portal Generator Addon To Priority Erp (developed By Soft Solutions)
Vendors & Products Priority
Priority portal Generator Addon To Priority Erp (developed By Soft Solutions)

Thu, 13 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Description CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
Title Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Priority Portal Generator Addon To Priority Erp (developed By Soft Solutions)
cve-icon MITRE

Status: PUBLISHED

Assigner: INCD

Published:

Updated: 2026-08-24T16:17:23.926Z

Reserved: 2026-07-05T09:17:04.753Z

Link: CVE-2026-59503

cve-icon Vulnrichment

Updated: 2026-08-13T14:37:03.227Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T10:17:15.380

Modified: 2026-08-28T16:08:44.147

Link: CVE-2026-59503

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:15:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor