Summary
CVE-2026-59499 is a high-severity information disclosure vulnerability affecting the Portal Generator addon for Priority ERP, developed by SoftSolutions (acquired by Priority Software). The flaw is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and allows a remote, unauthenticated attacker to access sensitive data over the network without any user interaction. With a CVSS v3.1 base score of 8.6, this issue poses a significant risk to any internet-exposed Priority ERP Portal Generator deployment.
Technical details
- Root cause: The Portal Generator addon exposes sensitive information to unauthorized actors due to improper access controls, as classified under CWE-200.
- Trigger conditions: Exploitation requires only network access to an exposed instance of the Portal Generator addon — no authentication, privileges, or user interaction are needed.
- Attack vector: Network (AV:N), with low attack complexity (AC:L), no privileges required (PR:N), and no user interaction (UI:N).
- Impact: High confidentiality impact (C:H) with a changed scope (S:C), meaning the vulnerability can expose sensitive information beyond the vulnerable component itself. There is no impact to integrity or availability.
Affected software
- Priority ERP Portal Generator addon (developed by SoftSolutions) — all versions that do not include Priwall v3.
Severity
- CVSS v3.1 Base Score: 8.6 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Upgrade to a version of the Portal Generator addon that includes Priwall v3, which addresses this exposure.
- If no patch is available: Do not expose Priority ERP Portal Generator infrastructure directly to the internet. Organizations still relying on the legacy Portal Generator should restrict network access to trusted internal sources only.
- Long-term: Consider migrating to Modern Priority Portals, the current portal offering from Priority Software, as recommended in the vendor’s guidance for this issue.

