Summary
CVE-2026-59507 is a critical vulnerability affecting the Portal Generator addon for Priority ERP, developed by Soft Solutions. The issue stems from a combination of hardcoded credentials, exposure of sensitive information, and improper access control, allowing an unauthenticated network attacker to gain unauthorized access to sensitive Priority ERP data. The vulnerability carries a CVSS v3.1 base score of 9.3 (Critical).
Technical details
- Root cause: The Portal Generator addon contains hardcoded credentials (CWE-798) combined with improper access control (CWE-284), which together lead to exposure of sensitive information (CWE-200).
- Trigger conditions: Any deployment of the Priority Portal Generator addon that does not run Priwall v3 is affected; no special configuration is required beyond network exposure of the portal.
- Attack vector: Network-based; the vector string indicates no privileges and no user interaction are required to exploit the flaw (AV:N/AC:L/PR:N/UI:N).
- Impact: Successful exploitation results in high confidentiality impact and low integrity impact, with a changed scope (S:C), meaning the vulnerability can affect resources beyond the vulnerable component itself — consistent with exposure of underlying Priority ERP data/infrastructure to unauthorized actors.
- Credit: The vulnerability was reported by HackersEye and published via Israel’s national CVE Numbering Authority (advisory ILVN-2026-0273).
Affected software
- Priority Portal Generator addon to Priority ERP (developed by Soft Solutions) — all versions that do not include Priwall v3.
Severity
- CVSS v3.1 Base Score: 9.3 (Critical)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Mitigation and recommended actions
- Immediate: Upgrade the Portal Generator addon to a version that incorporates Priwall v3, which addresses the hardcoded credentials and access control issues described in this CVE.
- If immediate patching/upgrade is not possible:
- Avoid exposing Priority Portal Generator infrastructure directly to the internet; restrict access to trusted internal networks or via VPN.
- Where feasible, migrate to Modern Priority Portals offered by Priority Software, which are not affected by this legacy addon vulnerability.
- Audit any externally reachable Priority Portal Generator instances for signs of unauthorized access, given the low complexity and lack of authentication required for exploitation.

