CVE-2026-59499 PUBLISHED

Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Assigner: INCD
Reserved: 05.07.2026 Published: 13.08.2026 Updated: 13.08.2026

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVSS Score: 8.6

Product Status

Vendor Priority
Product Portal Generator addon to Priority ERP (developed by Soft Solutions).
Versions Default: unaffected
  • Version All versions without Priwall v3 is affected

Solutions

Either do not expose your Priority infrastructure to the internet, or use Modern Priority Portals by Priority Software.

Credits

  • HackersEye finder

References

Problem Types

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE