Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2368+ Articles
158+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. Security
  3. CVE-2026-59500: Priority Portal Generator Authentication Bypass — CVSS 10.0
CVE-2026-59500: Priority Portal Generator Authentication Bypass — CVSS 10.0

Critical Security Alert

This vulnerability is actively being exploited. Immediate action is recommended.

SECURITYCRITICALCVE-2026-59500

CVE-2026-59500: Priority Portal Generator Authentication Bypass — CVSS 10.0

Maximum severity CVE in Priority ERP's portal addon allows unauthenticated remote attackers to bypass authentication entirely. Patch immediately.

Dylan H.

Security Team

August 14, 2026
3 min read

Affected Products

  • Priority Portal Generator (Priwall) by Soft Solutions — all versions prior to Priwall v3

Overview

A CVSS 10.0 vulnerability has been disclosed in the Priority Portal Generator addon for Priority ERP, developed by Soft Solutions. CVE-2026-59500 describes a complete authentication bypass — the highest possible severity rating — allowing unauthenticated remote attackers to bypass authentication mechanisms and gain unauthorized access with scope change across system boundaries.

The Israel National Cyber Directorate issued the advisory on August 13, 2026, alongside the related CVE-2026-59504 (CVSS 9.1) in the same product.

Technical Details

The flaw is classified as CWE-287: Improper Authentication. Authentication mechanisms fail to correctly verify the identity of actors attempting to access the system, allowing requests to bypass login entirely.

CVSS 3.1 vector breakdown:

  • Attack Vector: Network — no physical or local access required
  • Attack Complexity: Low — no special conditions or race conditions needed
  • Privileges Required: None — fully unauthenticated exploitation
  • User Interaction: None
  • Scope: Changed — impact crosses system boundaries beyond the vulnerable component
  • Impact: High Confidentiality, High Integrity, no Availability impact

The scope change is a key factor in reaching CVSS 10.0. An attacker successfully bypassing authentication is not just constrained to the portal component — access extends into integrated Priority ERP data and potentially connected systems.

Affected Product

  • Product: Priority Portal Generator (Priwall) by Soft Solutions
  • Integration: Addon module for the Priority ERP platform
  • Affected versions: All versions prior to Priwall v3

Remediation

Upgrade to Priwall v3 immediately. This is the sole remediation for CVE-2026-59500.

Interim mitigations while patching:

  • Take Priority Portal instances offline or restrict to VPN/intranet access only
  • Block public internet access to the portal at the network perimeter
  • Enable detailed authentication logging and review for unauthorized access attempts
  • Treat any portal instance that was internet-exposed prior to patching as potentially compromised — conduct a thorough access audit

Paired Disclosure: CVE-2026-59504

CVE-2026-59500 was published alongside CVE-2026-59504 (CVSS 9.1, client-side security bypass) in the same product. The combination of authentication bypass and client-side control bypass in a single product represents a serious compounded risk. Both are resolved by upgrading to Priwall v3.

Why This Matters

Priority ERP is widely deployed across manufacturing, logistics, retail, and government sectors, particularly in Israel and surrounding regions. An authentication bypass in the customer-facing portal module exposes business-critical ERP data to unauthenticated external attackers — including financial records, inventory, HR data, and operational planning information.

With CVSS 10.0 and a changed scope, CVE-2026-59500 should be treated with the same urgency as critical infrastructure vulnerabilities. If your organization uses Priority ERP with the portal addon, audit exposure now.

References

  • NVD: CVE-2026-59500
  • Israel National Cyber Directorate — CVE Advisories
#CVE#ERP#Authentication Bypass#Priority ERP#CWE-287#Critical

Related Articles

CVE-2026-59504: Priority Portal Generator Client-Side Security Bypass (CVSS 9.1)

Critical flaw in Soft Solutions' Priority ERP portal addon lets remote attackers bypass server-side security controls. Upgrade to Priwall v3.

2 min read

PicketLink SAML Authentication Bypass — Forged Assertions Accepted Without Validation

CVE-2026-10579 (CVSS 9.8): PicketLink Federation's SAML handler accepts forged assertions, allowing unauthenticated remote attackers to authenticate as any user.

4 min read

CVE-2026-8457: WooCommerce Social Login Authentication Bypass (CVSS 9.8)

A critical authentication bypass vulnerability in the WooCommerce - Social Login WordPress plugin allows unauthenticated attackers to log in as any registered user by exploiting a missing JWT signature verification in the Apple login handler.

3 min read
Back to all Security Alerts