CVE-2026-94496

Source
https://cve.org/CVERecord?id=CVE-2026-94496
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94496.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-94496
Published
2026-09-21T18:16:17Z
Modified
2026-09-22T03:45:35Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
jshERP through 3.6 Privilege Escalation via Role Management
Details

jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify any role's data scope or delete roles. Attackers can exploit the /role/update and /role/delete endpoints to escalate privileges, change data visibility to all data, and access all business records in the tenant.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-862"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94496.json"
}
References

Affected packages

Git / github.com/jishenghua/jsherp

Affected ranges

Type
GIT
Repo
https://github.com/jishenghua/jsherp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "3.6"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

v1.*
v1.0
v1.5
v2.*
v2.0
v2.1
v2.3
v2.3.1
v3.*
v3.0
v3.1
v3.2
v3.3
v3.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94496.json"