## VULNERABILITY RESEARCH

Priority Portal Generator — 9 CVEs & Vulnerability Research

Research by Roei Hadashi and Dean Bar at HackersEye.

Portal Generator served the internal ERP server address, the gateway in front of it, the application secret, the licence key, and a working API username and password to every visitor before login. Credential encryption ran client-side in JavaScript, so it protected nothing.

Around 415 vulnerable instances were found online, 269 of them in Israel, many serving hundreds of downstream businesses. Roughly 2,278 accessible data sets were reachable, including financial records, customer data and user accounts.

Affected product: Portal Generator addon to Priority ERP (developed by Soft Solutions). Not affected when Priwall v3 is deployed. CVE records assigned by INCD. Discovered November 2025, disclosed 13 August 2026.

CVES
9
CRITICAL
5
HIGH
3
MEDIUM
1
MAX CVSS
10.0
read the full technical writeup on hackerseye.com →

## THE RECORDS

CVE-2026-59500

Improper Authentication (CWE-287)

CVSS v3.1
10.0
Severity
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

CVE-2026-59506

Missing Authentication for Critical Function (CWE-306)

CVSS v3.1
9.3
Severity
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

CVE-2026-59507

Use of Hard-coded Credentials (CWE-798)

CVSS v3.1
9.3
Severity
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

CVE-2026-59503

Exposure of Private Personal Information (CWE-359)

CVSS v3.1
9.1
Severity
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CVE-2026-59504

Client-Side Enforcement of Server-Side Security (CWE-602)

CVSS v3.1
9.1
Severity
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CVE-2026-59499

Exposure of Sensitive Information (CWE-200)

CVSS v3.1
8.6
Severity
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CVE-2026-59505

Improper Access Control (CWE-284)

CVSS v3.1
8.6
Severity
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CVE-2026-59501

Improper Access Control (CWE-284)

CVSS v3.1
8.2
Severity
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CVE-2026-59502

Observable Discrepancy (CWE-203)

CVSS v3.1
5.3
Severity
MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

← back to roeihadashi.com