High severity8.8NVD Advisory· Published Sep 21, 2026
CVE-2026-94501
CVE-2026-94501
Description
jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without privilege checks. Attackers can manipulate user-role mappings and access controls to escalate privileges, strip access from other accounts, or modify role-function relationships for any user in the tenant.
Patches
Vulnerability mechanics
References
3- github.com/LinYuanyi1/cve-request-poc/blob/master/jshERP/poc-07-userbusiness-authorization-delete.pynvd
- github.com/jishenghua/jshERP/blob/v3.6/jshERP-boot/src/main/java/com/jsh/erp/controller/UserBusinessController.javanvd
- www.vulncheck.com/advisories/jsherp-through-3.6-privilege-escalation-via-userbusiness-crudnvd
News mentions
0No linked articles in our index yet.