<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Aureus ERP (&lt; 1.5.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/aureus-erp--1.5.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 22 Sep 2026 16:38:29 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/aureus-erp--1.5.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in Aureus ERP ChatterPanel</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-95655-aureus-erp/</link><pubDate>Tue, 22 Sep 2026 16:38:29 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-95655-aureus-erp/</guid><description>Aureus ERP versions prior to 1.5.0 contain an authorization bypass in the ChatterPanel component, allowing authenticated users to access and manipulate arbitrary messages via ID enumeration.</description><content:encoded><![CDATA[<p>Aureus ERP versions prior to 1.5.0 are vulnerable to an authorization bypass flaw within the ChatterPanel component. The application fails to properly scope message lookups to the current user's session or record, allowing any authenticated user to interact with arbitrary messages across the entire organization. By submitting sequential message IDs to the affected API endpoints, an attacker can read, edit, delete, or pin messages belonging to other departments or entities. This vulnerability poses a significant risk to organizational confidentiality and integrity, as it facilitates the mass enumeration of internal notes and unauthorized modification of business communication records. Defenders should prioritize patching affected instances to version 1.5.0 or later to mitigate this risk.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an authenticated attacker to compromise internal communications. Potential consequences include the unauthorized exfiltration of sensitive organizational data, manipulation of business records, and the ability to pin or delete critical messages. Given the vulnerability allows for enumeration of all notes in the system, the scope of the impact can span the entire organization, potentially affecting all departments.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Aureus ERP to version 1.5.0 or later immediately to resolve the authorization logic flaw in the ChatterPanel component (CVE-2026-95655).</li>
<li>Review web server access logs for anomalous patterns of sequential ID requests directed at API endpoints associated with the ChatterPanel module.</li>
<li>Implement strict server-side authorization checks on all record-retrieval functions to ensure that users are scoped only to data they are explicitly permitted to access.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>