{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aaureuserp/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:aureus:erp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-95655"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Aureus ERP (\u003c 1.5.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Aureus"],"content_html":"\u003cp\u003eAureus ERP versions prior to 1.5.0 are vulnerable to an authorization bypass flaw within the ChatterPanel component. The application fails to properly scope message lookups to the current user's session or record, allowing any authenticated user to interact with arbitrary messages across the entire organization. By submitting sequential message IDs to the affected API endpoints, an attacker can read, edit, delete, or pin messages belonging to other departments or entities. This vulnerability poses a significant risk to organizational confidentiality and integrity, as it facilitates the mass enumeration of internal notes and unauthorized modification of business communication records. Defenders should prioritize patching affected instances to version 1.5.0 or later to mitigate this risk.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to compromise internal communications. Potential consequences include the unauthorized exfiltration of sensitive organizational data, manipulation of business records, and the ability to pin or delete critical messages. Given the vulnerability allows for enumeration of all notes in the system, the scope of the impact can span the entire organization, potentially affecting all departments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Aureus ERP to version 1.5.0 or later immediately to resolve the authorization logic flaw in the ChatterPanel component (CVE-2026-95655).\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous patterns of sequential ID requests directed at API endpoints associated with the ChatterPanel module.\u003c/li\u003e\n\u003cli\u003eImplement strict server-side authorization checks on all record-retrieval functions to ensure that users are scoped only to data they are explicitly permitted to access.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T16:38:29Z","date_published":"2026-09-22T16:38:29Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-95655-aureus-erp/","summary":"Aureus ERP versions prior to 1.5.0 contain an authorization bypass in the ChatterPanel component, allowing authenticated users to access and manipulate arbitrary messages via ID enumeration.","title":"Authorization Bypass in Aureus ERP ChatterPanel","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-95655-aureus-erp/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:aureus:erp:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}