Summary
CVE-2026-59501 is an improper access control vulnerability (CWE-284) affecting the Portal Generator addon for Priority ERP, developed by Soft Solutions (acquired by Priority Software). The flaw allows unauthenticated, network-based access to sensitive data on affected Priority ERP portal deployments. It carries a CVSS v3.1 base score of 8.2 (High) and impacts any instance of the addon that has not been upgraded to the Priwall v3 protection layer.
Technical details
- Root cause: The Portal Generator addon fails to properly enforce access control on portal-exposed resources, classified under CWE-284 (Improper Access Control).
- Trigger conditions: Exploitation requires no authentication and no user interaction; the vulnerable functionality is reachable directly over the network wherever the affected portal is exposed to the internet or an internal network.
- Attack vector: Network (AV:N) — a remote, unauthenticated attacker can send requests directly to the exposed portal to trigger the access control flaw.
- Impact: The vulnerability results in a high confidentiality impact, allowing unauthorized disclosure of sensitive data (C:H). It also carries a low integrity impact (I:L). There is no impact to availability (A:N), and successful exploitation does not require privileges or user interaction, making it especially attractive to opportunistic scanning and automated exploitation attempts.
Affected software
- Portal Generator addon to Priority ERP (developed by Soft Solutions)
- All versions of the addon that do not have the Priwall v3 protection layer implemented
Severity
- CVSS v3.1 Base Score: 8.2 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Mitigation and recommended actions
- Immediate: Deploy or upgrade to Priwall v3, the protection layer that addresses this improper access control issue, on all Portal Generator addon instances.
- If Priwall v3 cannot be deployed immediately: Organizations should isolate internet-facing Priority ERP Portal Generator instances from public/untrusted network exposure and restrict access to trusted networks only until the protection layer is applied.
- Longer term: Priority Software recommends organizations transition to its modern Priority Portal offerings, which supersede the legacy Portal Generator addon, to reduce exposure to this class of access control weakness.
- Security teams should audit internet-facing assets for exposed Priority ERP Portal Generator instances and prioritize remediation given the unauthenticated, network-exploitable nature of this vulnerability.

