CVE-2026-59500
10.0Priority · Portal Generator addon to Priority ERP
The Portal Generator addon to Priority ERP is vulnerable to improper authentication, which may allow unauthorized access to the application infrastructure.
Executive summary
A critical authentication bypass vulnerability in the Priority Portal Generator addon exposes ERP infrastructure to unauthorized access and potential data compromise.
Vulnerability
The vulnerability is categorized as CWE-287, Improper Authentication. It allows an unauthenticated, remote attacker to bypass security controls and potentially gain unauthorized access to the Priority ERP environment.
Business impact
With a CVSS score of 10.0, this vulnerability presents an extreme risk to the confidentiality and integrity of business-critical ERP data. Unauthorized access could lead to the exposure of sensitive financial or operational information, and the potential for attackers to perform unauthorized transactions within the system.
Remediation
Immediate Action: Restrict internet access to the Priority ERP infrastructure or transition to the Modern Priority Portals provided by Priority Software.
Proactive Monitoring: Review authentication logs for irregular login patterns and unauthorized access attempts targeting the portal interface.
Compensating Controls: Implement strict network-level access controls, such as VPN requirements or IP allowlisting, to ensure that only authorized users can reach the portal infrastructure.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability necessitates immediate action to prevent unauthorized access. Organizations should prioritize isolating the affected portal from the public internet until they can migrate to the recommended secure infrastructure.