Privilege Escalation Vulnerability in jshERP 3.6 by jishenghua
CVE-2026-94411
Key Information:
- Vendor
Jishenghua
- Status
- Vendor
- CVE Published:
- 21 September 2026
Badges
What is CVE-2026-94411?
jshERP version 3.6 is susceptible to a privilege escalation vulnerability found within the updateOneValueByKeyIdAndType endpoint. This flaw allows authenticated users to manipulate their access privileges unlawfully. By submitting a POST request containing their user ID and a list of role IDs designated for escalation, low-privilege users can unjustly elevate their permissions to that of a tenant administrator. This security oversight presents significant risks as it enables potential attackers to gain elevated access, thereby compromising the integrity and confidentiality of the system.
Affected Version(s)
jshERP 3.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
