
🚨Critical - Priority ERP Portal Generator Improper Authentication (CVE-2026-59500) The Portal Generator addon for Priority ERP (by Soft Solutions) contains an improper-authentication flaw. Per the Israel National Cyber Directorate, it scores the maximum CVSS 10.0: an unauthenticated remote attacker, with no user interaction, can bypass authentication and gain high-impact read and write access, and the issue is scope-changing. Because these portals sit on top of Priority ERP, which holds financial, operational, and customer data, unauthorized access is serious. All versions without Priwall v3 are affected. Public technical detail is currently limited. 👉Apply Priwall v3 to the Portal Generator addon per the INCD advisory, and restrict portal exposure.
Post summary
CVE‑2026‑59500 reveals an improper authentication flaw in Priority ERP Portal Generator that allows unauthenticated remote attackers to gain full access; the Israel National Cyber Directorate recommends applying Priwall v3 as a mitigation.
