Overview
A CVSS 10.0 vulnerability has been disclosed in the Priority Portal Generator addon for Priority ERP, developed by Soft Solutions. CVE-2026-59500 describes a complete authentication bypass — the highest possible severity rating — allowing unauthenticated remote attackers to bypass authentication mechanisms and gain unauthorized access with scope change across system boundaries.
The Israel National Cyber Directorate issued the advisory on August 13, 2026, alongside the related CVE-2026-59504 (CVSS 9.1) in the same product.
Technical Details
The flaw is classified as CWE-287: Improper Authentication. Authentication mechanisms fail to correctly verify the identity of actors attempting to access the system, allowing requests to bypass login entirely.
CVSS 3.1 vector breakdown:
- Attack Vector: Network — no physical or local access required
- Attack Complexity: Low — no special conditions or race conditions needed
- Privileges Required: None — fully unauthenticated exploitation
- User Interaction: None
- Scope: Changed — impact crosses system boundaries beyond the vulnerable component
- Impact: High Confidentiality, High Integrity, no Availability impact
The scope change is a key factor in reaching CVSS 10.0. An attacker successfully bypassing authentication is not just constrained to the portal component — access extends into integrated Priority ERP data and potentially connected systems.
Affected Product
- Product: Priority Portal Generator (Priwall) by Soft Solutions
- Integration: Addon module for the Priority ERP platform
- Affected versions: All versions prior to Priwall v3
Remediation
Upgrade to Priwall v3 immediately. This is the sole remediation for CVE-2026-59500.
Interim mitigations while patching:
- Take Priority Portal instances offline or restrict to VPN/intranet access only
- Block public internet access to the portal at the network perimeter
- Enable detailed authentication logging and review for unauthorized access attempts
- Treat any portal instance that was internet-exposed prior to patching as potentially compromised — conduct a thorough access audit
Paired Disclosure: CVE-2026-59504
CVE-2026-59500 was published alongside CVE-2026-59504 (CVSS 9.1, client-side security bypass) in the same product. The combination of authentication bypass and client-side control bypass in a single product represents a serious compounded risk. Both are resolved by upgrading to Priwall v3.
Why This Matters
Priority ERP is widely deployed across manufacturing, logistics, retail, and government sectors, particularly in Israel and surrounding regions. An authentication bypass in the customer-facing portal module exposes business-critical ERP data to unauthenticated external attackers — including financial records, inventory, HR data, and operational planning information.
With CVSS 10.0 and a changed scope, CVE-2026-59500 should be treated with the same urgency as critical infrastructure vulnerabilities. If your organization uses Priority ERP with the portal addon, audit exposure now.