{"id":"CVE-2026-94501","published":"2026-09-21T19:17:21.910","lastModified":"2026-09-22T20:43:58.793","description":"jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without privilege checks. Attackers can manipulate user-role mappings and access controls to escalate privileges, strip access from other accounts, or modify role-function relationships for any user in the tenant.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://github.com/LinYuanyi1/cve-request-poc/blob/master/jshERP/poc-07-userbusiness-authorization-delete.py","tags":[]},{"url":"https://github.com/jishenghua/jshERP","tags":[]},{"url":"https://github.com/jishenghua/jshERP/blob/v3.6/jshERP-boot/src/main/java/com/jsh/erp/controller/UserBusinessController.java#L50-L80","tags":[]},{"url":"https://www.vulncheck.com/advisories/jsherp-through-3.6-privilege-escalation-via-userbusiness-crud","tags":[]}],"exploitRefs":[{"url":"https://github.com/LinYuanyi1/cve-request-poc/blob/master/jshERP/poc-07-userbusiness-authorization-delete.py","tags":[]},{"url":"https://github.com/jishenghua/jshERP","tags":[]},{"url":"https://github.com/jishenghua/jshERP/blob/v3.6/jshERP-boot/src/main/java/com/jsh/erp/controller/UserBusinessController.java#L50-L80","tags":[]}],"hasPoc":true,"ai":{"summary":"This vulnerability allows authenticated users to bypass authorization checks and manipulate user-role mappings, leading to potential privilege escalation and access control modifications.","exploitability":"Exploitation requires an authenticated user with access to the userBusiness CRUD endpoints. The vulnerability is relatively easy to exploit given the preconditions.","blast_radius":"If exploited, attackers can escalate privileges, strip access from other accounts, or modify role-function relationships for any user in the tenant, leading to significant damage.","remediation":"Upgrade to jshERP 3.61 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","web","priv-escalation"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:16:08.502Z"}}