CVE-2026-94494

MEDIUMCVSS 5.0

jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint. Attackers can iterate the primary key to enumerate and access sensitive tenant data including login names, validity dates, user quotas, and enabled state across all platform tenants.

Published 2026-09-21 · last modified 2026-09-21

Full record at NVD ↗

← Get alerted the moment a CVE hits your gear — subscribe free

Ncerio by BeyondNets · data from NVD, CISA KEV, EPSS.