CVE-2026-94497: Jishenghua Jsherp
High severity, CVSS 8.3. EPSS: 0.5% chance of exploitation in the next 30 days.
jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and delete other users' business objects by submitting direct object identifiers without authorization checks.
Affected products
- Jishenghua Jsherp: up to and including 3.6
Published 2026-09-21. Last modified 2026-09-22.