{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/jsherp--3.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:jsherp:jsherp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-94411"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["jshERP (3.6)","jshERP (\u003c= 3.6)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","web-application","authorization-bypass","idor","insecure-direct-object-reference"],"_cs_type":"advisory","_cs_vendors":["jshERP"],"content_html":"\u003cp\u003ejshERP version 3.6 is vulnerable to a privilege escalation flaw located within the updateOneValueByKeyIdAndType endpoint. This vulnerability stems from improper access control, enabling an authenticated low-privilege tenant user to modify their own account permissions. By submitting a crafted POST request, an attacker can specify the type parameter as UserRole and supply a chosen role ID list, effectively granting themselves administrative privileges within the tenant environment. This vulnerability, tracked as CVE-2026-94411, carries a CVSS v3.1 base score of 8.8. It represents a significant security risk for organizations relying on jshERP for multi-tenant enterprise resource planning, as it allows for horizontal and vertical privilege escalation without requiring existing administrative access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a low-privileged tenant user to gain full administrative control over their tenant account. This results in the potential for unauthorized data access, modification, or deletion of sensitive business information and configuration settings stored within the jshERP instance. Given the nature of the application as an ERP system, unauthorized administrative access poses a severe risk to data integrity and business operations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize remediation by identifying and patching instances of jshERP 3.6. If a patch is not immediately available, restrict access to the web interface from untrusted networks and audit logs for unauthorized requests to the updateOneValueByKeyIdAndType endpoint.\u003c/p\u003e\n\u003ch2 id=\"detection\"\u003eDetection\u003c/h2\u003e\n\u003cp\u003eDetecting this exploitation requires monitoring web server logs for suspicious POST requests targeting the identified API endpoint.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web access logs for HTTP POST requests to the /updateOneValueByKeyIdAndType endpoint where the request body contains 'type=UserRole' and parameters indicative of role modification.\u003c/li\u003e\n\u003cli\u003eAudit user management activities and privilege changes within the application logs to identify anomalous account elevation events.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-21T20:30:23Z","date_published":"2026-09-21T20:30:00Z","id":"https://feed.craftedsignal.io/briefs/2026-09-jsherp-priv-esc/","summary":"jshERP 3.6 contains an improper access control vulnerability in the updateOneValueByKeyIdAndType endpoint allowing authenticated users to escalate privileges to tenant administrator.","title":"Privilege Escalation in jshERP 3.6 via updateOneValueByKeyIdAndType","url":"https://feed.craftedsignal.io/briefs/2026-09-jsherp-priv-esc/"}],"language":"en","title":"CraftedSignal Threat Feed - JshERP (\u003c= 3.6)","version":"https://jsonfeed.org/version/1.1"}