CVE-2026-94494: Jishenghua Jsherp
Medium severity, CVSS 5.0. EPSS: 0.4% chance of exploitation in the next 30 days.
jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint. Attackers can iterate the primary key to enumerate and access sensitive tenant data including login names, validity dates, user quotas, and enabled state across all platform tenants.
Affected products
- Jishenghua Jsherp: up to and including 3.6
Published 2026-09-21. Last modified 2026-09-22.