CVE-2026-59507 PUBLISHED

Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control

Assigner: INCD
Reserved: 05.07.2026 Published: 13.08.2026 Updated: 13.08.2026

CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
CVSS Score: 9.3

Product Status

Vendor Priority
Product Portal Generator addon to Priority ERP (developed by Soft Solutions)
Versions Default: affected
  • Version All versions without Priwall v3 is affected

Solutions

Either do not expose your Priority infrastructure to the internet, or use Modern Priority Portals by Priority Software

Credits

  • HackersEye finder

References

Problem Types

  • CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control CWE