Improper Authorization Vulnerability in jishenghua jshERP Financial Receipt Update Handler
CVE-2026-105621
Key Information:
- Vendor
Jishenghua
- Status
- Vendor
- CVE Published:
- 6 October 2026
Badges
What is CVE-2026-105621?
A security flaw has been identified in the jishenghua jshERP software, specifically within the Financial Receipt Update Handler. The vulnerability resides in the updateAccountHeadAndDetail function of the AccountHeadService.java class. It allows an attacker to perform unauthorized actions remotely due to improper authorization checks. This issue was reported to the project maintainers, but no response has been noted, raising concerns about the potential for widespread exploitation. As the exploit has been publicly released, users are advised to take immediate precautions.
Affected Version(s)
jshERP 3.0
jshERP 3.1
jshERP 3.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
