
CVE@CVEnew
CVE-2026-94497 jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify… https://www.cve.org/CVERecord?id=CVE-2026-94497
00000851
58.1K followersView on X
