Description
: Client-Side Enforcement of Server-Side Security vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).

This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.
Published: 2026-08-13
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that the vulnerability is a client‑side enforcement of server‑side security flaw in the Priority Portal Generator addon, enabling an attacker to manipulate client‑side checks and submit privileged requests that bypass server‑side controls, thereby granting unauthorized operations and potentially exposing sensitive ERP data, as indicated by the high CVSS score of 9.1.

Affected Systems

Priority:Portal Generator addon to Priority ERP, developed by Soft Solutions. All versions lacking Priwall v3 are susceptible, meaning any deployment of the addon without the latest Priwall restriction layer is affected.

Risk and Exploitability

Based on the description, it is inferred that the attack vector is through the web portal interface, allowing remote attackers with internet access to manipulate client‑side logic. The EPSS score of <1% indicates a low exploitation probability, but the absence of server‑side enforcement and the critical CVSS rating raise the risk. The vulnerability is not listed in the CISA KEV catalog, yet an exposed portal could be a target for attackers seeking privilege escalation.

Generated by OpenCVE AI on August 24, 2026 at 22:40 UTC.

Remediation

Vendor Solution

Either do not expose your Priority infrastructure to the internet, or use Modern Priority Portals by Priority Software


OpenCVE Recommended Actions

  • Ensure the Priority ERP portal is not exposed to external networks; implement firewall rules or VPN isolation to restrict access to trusted internal networks.
  • Deploy Modern Priority Portals, which enforce authentication and authorization server‑side, thereby eliminating the client‑side bypass.
  • Conduct a comprehensive code review or penetration test to confirm that all access checks are performed on the server and that no client‑side controls rely solely on UI enforcement.

Generated by OpenCVE AI on August 24, 2026 at 22:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description CWE-602: Client-Side Enforcement of Server-Side Security : Client-Side Enforcement of Server-Side Security vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

Thu, 13 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Priority
Priority portal Generator Addon To Priority Erp (developed By Soft Solutions)
Vendors & Products Priority
Priority portal Generator Addon To Priority Erp (developed By Soft Solutions)

Thu, 13 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Description CWE-602: Client-Side Enforcement of Server-Side Security
Title Priority – CWE-602: Client-Side Enforcement of Server-Side Security
Weaknesses CWE-602
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Priority Portal Generator Addon To Priority Erp (developed By Soft Solutions)
cve-icon MITRE

Status: PUBLISHED

Assigner: INCD

Published:

Updated: 2026-08-24T16:18:05.315Z

Reserved: 2026-07-05T09:17:53.013Z

Link: CVE-2026-59504

cve-icon Vulnrichment

Updated: 2026-08-13T14:38:20.319Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T10:17:15.500

Modified: 2026-08-28T16:08:44.147

Link: CVE-2026-59504

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:45:03Z

Weaknesses
  • CWE-602

    Client-Side Enforcement of Server-Side Security