Summary
CVE-2026-59500 is a critical improper authentication vulnerability (CWE-287) affecting the Portal Generator addon for Priority ERP, developed by Soft Solutions. The flaw allows a remote, unauthenticated attacker to bypass authentication controls over the network, resulting in a critical confidentiality impact. The vulnerability carries the maximum CVSS v3.1 base score of 10.0.
Technical details
- Root cause: Improper authentication (CWE-287) in the Portal Generator addon, which allows the identity of a user or component to be assumed without proper verification.
- Trigger conditions: No privileges and no user interaction are required; the flaw is exploitable directly over the network against internet-exposed Priority ERP Portal Generator deployments that do not run Priwall v3.
- Attack vector: Network (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: The scope is changed (S:C), indicating the vulnerability can affect resources beyond the vulnerable component’s own security scope. Confidentiality impact is high (C:H); integrity and availability are not impacted per the published vector (I:H per the vector actually indicates integrity is also high — see Severity section for the exact string). Successful exploitation allows an unauthenticated attacker to bypass authentication and access protected functionality/data exposed via the Portal Generator addon.
Affected software
- Product: Portal Generator addon to Priority ERP (developed by Soft Solutions)
- Versions affected: All versions that do not incorporate Priwall v3
Severity
- CVSS v3.1 Base Score: 10.0 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Upgrade to a Portal Generator deployment that incorporates Priwall v3, which addresses this authentication bypass.
- Recommended long-term action: Migrate to Priority Software’s Modern Priority Portals, as recommended in the vendor’s advisory.
- If patching is not immediately possible: Do not expose Priority ERP Portal Generator infrastructure directly to the internet. Restrict network access to trusted, internal networks only (e.g., via VPN or firewall allow-listing) until Priwall v3 is deployed.
- Additional recommendation: Audit existing Portal Generator deployments for internet exposure and monitor for anomalous authentication activity or unauthorized access attempts.

