Improper Access Control and Hard-coded Credentials in Popular Vendor Product
CVE-2026-59507

9.3CRITICAL

What is CVE-2026-59507?

The vulnerability arises from the presence of hard-coded credentials within the affected product, creating a severe risk of unauthorized access. This compromises sensitive information and allows malicious actors to leverage improper access control mechanisms, ultimately exposing users to potential data breaches. Security best practices underline the necessity of addressing hard-coded credentials to mitigate risks and enhance system integrity.

Affected Version(s)

Portal Generator addon to Priority ERP (developed by Soft Solutions) All versions without Priwall v3

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HackersEye
.