Unscoped Message Access Vulnerability in Aureus ERP by Aureus
CVE-2026-95655
8.6HIGH
What is CVE-2026-95655?
The Aureus ERP application prior to version 1.5.0 contains a vulnerability in the ChatterPanel feature, which fails to appropriately restrict message access. Authenticated users can exploit this flaw to access, modify, or delete messages from other users across various departments and organizations. By incrementing message IDs, attackers could enumerate and manipulate messages, presenting significant risks to data integrity and confidentiality within the system.
Affected Version(s)
aureuserp 0 < 1.5.0
aureuserp 1.5.0
