Authorization Bypass in jshERP Product by Vendor jshERP
CVE-2026-94412
Key Information:
- Vendor
Jishenghua
- Status
- Vendor
- CVE Published:
- 21 September 2026
Badges
What is CVE-2026-94412?
The jshERP application through version 3.6 contains a significant vulnerability in its password reset functionality. Specifically, the authorization bypass affects the POST /user/resetPwd endpoint, which allows authenticated users to reset passwords of any other user by simply specifying a target user ID. This flaw can be exploited by attackers to gain unauthorized access, potentially compromising sensitive accounts, including those of administrators. The vulnerability underscores the necessity for robust access controls and validation mechanisms to safeguard user data.
Affected Version(s)
jshERP 0 <= 3.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
