Description
: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).

This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.
Published: 2026-08-13
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Priority Portal Generator addon for Priority ERP lacks proper access controls, allowing unauthenticated or unauthorized users to read, modify, or delete ERP data through the web interface. All releases that do not include Priwall v3 are affected. Because the addon does not enforce permission checks, an attacker could exploit the flaw to compromise the confidentiality and integrity of the system.

Affected Systems

The Vista system in question is the Priority Portal Generator addon that integrates with Priority ERP, developed by Soft Solutions. All versions of the addon that do not include Priwall v3 are susceptible. If the portal is publicly reachable, it presents a risk, and any deployment of the addon that remains publicly exposed should be examined.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity. The EPSS score is less than 1% (approximately 0.3%), showing a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. This suggests that, although a public exploit may not yet exist, exposed portals still represent a significant risk. The likely attack vector is remote access over the network if the portal is exposed to the internet; an attacker could reach it and bypass the missing access checks. Consequently, the risk remains high if the portal is publicly reachable, even in the absence of an identified exploit. The recommended mitigation is to isolate the portal behind an internal network firewall or to replace it with the vendor‑issued Modern Portals that implement appropriate access controls.

Generated by OpenCVE AI on August 24, 2026 at 21:42 UTC.

Remediation

Vendor Solution

Either do not expose your Priority infrastructure to the internet, or use Modern Priority Portals by Priority Software


OpenCVE Recommended Actions

  • Ensure the Priority ERP infrastructure, particularly the Portal Generator addon, is not reachable from the public internet through firewall or network segmentation rules.
  • If possible, migrate to Priority Software’s Modern Portals, which incorporate proper access control mechanisms.
  • Review and tighten the addon’s authentication and authorization logic, ensuring that each request is checked against the user’s legitimate permissions before any ERP data is exposed or altered.

Generated by OpenCVE AI on August 24, 2026 at 21:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description CWE-284: Improper Access Control : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

Fri, 14 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Priority
Priority portal Generator Addon To Priority Erp (developed By Soft Solutions)
Vendors & Products Priority
Priority portal Generator Addon To Priority Erp (developed By Soft Solutions)

Thu, 13 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Description CWE-284: Improper Access Control
Title Priority - CWE-284: Improper Access Control
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Priority Portal Generator Addon To Priority Erp (developed By Soft Solutions)
cve-icon MITRE

Status: PUBLISHED

Assigner: INCD

Published:

Updated: 2026-08-24T16:18:46.283Z

Reserved: 2026-07-05T09:17:53.013Z

Link: CVE-2026-59505

cve-icon Vulnrichment

Updated: 2026-08-13T14:39:19.972Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T10:17:15.623

Modified: 2026-08-28T16:08:44.147

Link: CVE-2026-59505

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:45:03Z

Weaknesses