Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint. Attackers can iterate the primary key to enumerate and access sensitive tenant data including login names, validity dates, user quotas, and enabled state across all platform tenants. | |
| Title | jshERP through 3.6 Tenant Information Disclosure via GET /tenant/info | |
| First Time appeared |
Jishenghua
Jishenghua jsherp |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:jishenghua:jsherp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jishenghua
Jishenghua jsherp |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-21T19:19:58.792Z
Reserved: 2026-09-21T17:52:00.703Z
Link: CVE-2026-94494
Updated: 2026-09-21T19:19:52.442Z
Status : Received
Published: 2026-09-21T19:17:20.993
Modified: 2026-09-21T20:17:41.550
Link: CVE-2026-94494
No data.
OpenCVE Enrichment
Updated: 2026-09-21T19:45:17Z
-
CWE-639
Authorization Bypass Through User-Controlled Key