← Back to search

CVE-2026-94411

8.8 HIGHpublic exploit available

Published 2026-09-21 · Updated 2026-09-24

AI risk analysis

Summary
The vulnerability in jshERP 3.6 allows authenticated users to escalate their privileges by sending a POST request to the updateOneValueByKeyIdAndType endpoint, granting themselves arbitrary roles, including tenant administrator.
Exploitability
Exploitation is relatively straightforward for authenticated users who can send a crafted POST request. Precondition is having valid authentication credentials.
Blast radius
If exploited, attackers can gain full control over the system, leading to potential data breaches and system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to jshERP 3.6.1 or later.
auth-bypassprivilege-escalationweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles. Attackers can send a POST request with type=UserRole, their own user ID, and a role ID list to escalate from low-privilege tenant user to tenant administrator.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-862

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.