CVE-2026-94414
EUVD-2026-8404421.09.2026, 19:17
jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticated users to modify role button-permission definitions. Attackers can supply arbitrary roleId and btnStr parameters to overwrite button-permission configurations for any role in the tenant without privilege validation.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| jishenghua | jsherp | 𝑥 ≤ 3.6 | CNA |
Common Weakness Enumeration
References