CVE-2026-94411 | jishenghua jshERP 3.6 updateOneValueByKeyIdAndType endpoint poc-01-userbusiness-self-privilege-escalation.py type/user ID/role ID list privileges management

SecurityVulns

A vulnerability was found in jishenghua jshERP 3.6. It has been declared as critical. Impacted is the function updateOneValueByKeyIdAndType of the file poc-01-userbusiness-self-privilege-escalation.py of the component updateOneValueByKeyIdAndType endpoint. The manipulation of the argument type/user ID/role ID list results in improper privilege management.

This vulnerability is cataloged as CVE-2026-94411. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More