CVE-2026-59500
Improper Authentication (CWE-287)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
## VULNERABILITY RESEARCH
Research by Roei Hadashi and Dean Bar at HackersEye.
Portal Generator served the internal ERP server address, the gateway in front of it, the application secret, the licence key, and a working API username and password to every visitor before login. Credential encryption ran client-side in JavaScript, so it protected nothing.
Around 415 vulnerable instances were found online, 269 of them in Israel, many serving hundreds of downstream businesses. Roughly 2,278 accessible data sets were reachable, including financial records, customer data and user accounts.
Affected product: Portal Generator addon to Priority ERP (developed by Soft Solutions). Not affected when Priwall v3 is deployed. CVE records assigned by INCD. Discovered November 2025, disclosed 13 August 2026.
## THE RECORDS
Improper Authentication (CWE-287)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Missing Authentication for Critical Function (CWE-306)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Use of Hard-coded Credentials (CWE-798)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Exposure of Private Personal Information (CWE-359)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Client-Side Enforcement of Server-Side Security (CWE-602)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exposure of Sensitive Information (CWE-200)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Improper Access Control (CWE-284)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Improper Access Control (CWE-284)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Observable Discrepancy (CWE-203)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N