CVE-2026-59505

8.6

Priority · Portal Generator addon to Priority ERP

The Portal Generator addon for Priority ERP contains an improper access control vulnerability that allows unauthenticated attackers to bypass security restrictions.

Executive summary

An unauthenticated access control vulnerability in the Priority Portal Generator addon exposes the Priority ERP environment to potential unauthorized access.

Vulnerability

This vulnerability, categorized as CWE-284, represents a failure to properly restrict access to the Portal Generator component. An unauthenticated attacker can exploit this flaw to interact with the system in ways that should be prohibited by default security policies.

Business impact

The risk associated with this vulnerability is severe, as it allows attackers to potentially interact with the underlying Priority ERP system. With a CVSS score of 8.6, the compromise of an ERP system can lead to the exposure of sensitive business data, financial records, and operational disruptions, posing a critical threat to organizational integrity.

Remediation

Immediate Action: Either restrict external access to the Priority infrastructure or migrate to the Modern Priority Portals provided by Priority Software.

Proactive Monitoring: Monitor network traffic for unusual connections directed at the Portal Generator interface and audit user activity for suspicious data access patterns.

Compensating Controls: Implement strict network-level controls, such as VPN requirements or IP allowlisting, to ensure that the Portal Generator is not directly accessible from the public internet.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical nature of ERP systems, it is vital to secure the Portal Generator immediately. Administrators should prioritize moving away from vulnerable versions by implementing the vendor-recommended migration or by strictly isolating the affected infrastructure from the internet to mitigate the risk of unauthorized access.

More Priority CVEs