CVE-2026-94495 | jishenghua jshERP up to 3.6 SystemConfigService poc-10-systemconfig-tamper.py SystemConfigService.updateSystemConfig privileges management

SecurityVulns

A vulnerability categorized as problematic has been discovered in jishenghua jshERP up to 3.6. The impacted element is the function SystemConfigService.updateSystemConfig of the file poc-10-systemconfig-tamper.py of the component SystemConfigService. Such manipulation leads to improper privilege management.

This vulnerability is documented as CVE-2026-94495. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More