Description
: Missing Authentication for Critical Function vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).

This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.
Published: 2026-08-13
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authentication flaw in the Portal Generator addon to Priority ERP, which allows unauthenticated users to execute critical functions and access potentially sensitive data. This CWE‑306 weakness results in a high CVSS score of 9.3 and is considered a serious authentication bypass.

Affected Systems

The affected product is the Portal Generator addon for Priority ERP, developed by Soft Solutions. All versions of the addon that do not incorporate Priwall v3 are vulnerable; no further version specificity is listed in the advisory.

Risk and Exploitability

Because authentication is omitted, anyone able to reach the Portal Generator endpoint can exploit the flaw. The EPSS score of 0.00292 (0.292%) indicates a very low probability of exploitation in the near term, yet the high CVSS score exposes a severe risk if the addon is reachable from the Internet. The vulnerability is not listed in the CISA KEV catalog and no known exploits have been reported.

Generated by OpenCVE AI on August 24, 2026 at 22:13 UTC.

Remediation

Vendor Solution

Either do not expose your Priority infrastructure to the internet, or use Modern Priority Portals by Priority Software


OpenCVE Recommended Actions

  • Disable public exposure of the Priority infrastructure so that the Portal Generator addon is not accessible from the Internet
  • Restrict access to the addon to whitelisted internal IP addresses only and enforce network segmentation to isolate the ERP environment
  • Migrate to Modern Priority Portals provided by Priority Software, which include built‑in authentication and eliminate the missing authentication risk

Generated by OpenCVE AI on August 24, 2026 at 22:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description CWE-306: Missing Authentication for Critical Function : Missing Authentication for Critical Function vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

Fri, 14 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Priority
Priority portal Generator Addon To Priority Erp (developed By Soft Solutions)
Vendors & Products Priority
Priority portal Generator Addon To Priority Erp (developed By Soft Solutions)

Thu, 13 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Description CWE-306: Missing Authentication for Critical Function
Title Priority – CWE-306: Missing Authentication for Critical Function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Priority Portal Generator Addon To Priority Erp (developed By Soft Solutions)
cve-icon MITRE

Status: PUBLISHED

Assigner: INCD

Published:

Updated: 2026-08-24T16:19:14.597Z

Reserved: 2026-07-05T09:17:53.013Z

Link: CVE-2026-59506

cve-icon Vulnrichment

Updated: 2026-08-13T14:39:48.676Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T10:17:15.840

Modified: 2026-08-28T16:08:44.147

Link: CVE-2026-59506

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:15:13Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function