Summary
CVE-2026-59506 is a critical Missing Authentication for Critical Function vulnerability (CWE-306) affecting the Portal Generator addon to Priority ERP, developed by Soft Solutions. The flaw allows unauthenticated, network-based access to a critical function of the portal, resulting in high-impact exposure of confidential data. It carries a CVSS v3.1 base score of 9.3 (Critical) and was published by Israel’s National Cyber Directorate (INCD) on August 13, 2026.
Technical details
- Root cause: The Portal Generator addon fails to enforce authentication on a critical function, per CWE-306 (Missing Authentication for Critical Function).
- Trigger conditions: Exploitation requires no privileges and no user interaction; an attacker only needs network access to an internet-exposed instance of the affected portal.
- Attack vector: Network (AV:N), with low attack complexity (AC:L) — the vulnerability is reachable and exploitable directly over the network without prerequisites.
- Scope and impact: The CVSS vector indicates a changed scope (S:C), high confidentiality impact (C:H), and low integrity impact (I:L), with no availability impact (A:N) — consistent with unauthorized exposure/leakage of sensitive data and limited unauthorized modification, rather than denial of service.
- The advisory (ILVN-2026-0272) was issued by INCD, with the vulnerability credited to finder "HackersEye."
Affected software
- Vendor: Priority
- Product: Portal Generator addon to Priority ERP (developed by Soft Solutions)
- Affected versions: All versions of the Portal Generator addon that do not include Priwall v3 (i.e., any deployment lacking the Priwall v3 protection component is affected)
Severity
- CVSS v3.1 Base Score: 9.3 (Critical)
- Vector string:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Mitigation and recommended actions
- Immediate: Upgrade the Portal Generator addon to a version that includes Priwall v3, which addresses the missing authentication issue.
- If patching/upgrading is not immediately possible:
- Do not expose Priority Portal Generator infrastructure directly to the internet.
- Restrict network access to the portal to trusted internal networks or via a VPN/authenticated proxy until Priwall v3 is deployed.
- As a longer-term option, migrate to Modern Priority Portals by Priority Software, which is not affected by this issue.
- Security teams should treat any internet-facing Portal Generator instance without Priwall v3 as immediately exploitable and prioritize remediation given the unauthenticated, network-reachable nature of this flaw.

