## PRIORITY PORTAL GENERATOR / CVE-2026-59507

CVE-2026-59507

CWE-798 — Use of Hard-coded Credentials

CVSS v3.1
9.3
Severity
CRITICAL
Assigner
INCD
Disclosed
13 August 2026

Per its CVSS vector, this is reachable over the network, with no credentials, and no user interaction, under conditions the attacker fully controls.


## WHAT THE WEAKNESS MEANS

Credentials are embedded in the software itself. Every deployment shares them, nobody can rotate them, and anyone who obtains one copy holds a key to all of them.


## DECODED CVSS VECTOR

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

Attack vectorNetwork
Exploitable remotely, over the internet — no foothold on the network is needed first.
Attack complexityLow
No special conditions. The attack works reliably, every time, against any affected instance.
Privileges requiredNone
No account and no credentials. An anonymous visitor can do this.
User interactionNone
No victim needs to click, visit or approve anything. The attacker acts alone.
ScopeChanged
The blast radius escapes the vulnerable component and reaches systems beyond it — which is why this scores higher than the impact metrics alone would suggest.
Confidentiality impactHigh
Total loss of confidentiality — every piece of data the component can reach is readable by the attacker.
Integrity impactLow
Some data can be modified, but not arbitrarily, and the consequences are limited.
Availability impactNone
Availability is unaffected.

## AFFECTED & MITIGATION

Affected: Portal Generator addon to Priority ERP (developed by Soft Solutions), all versions without Priwall v3. Not affected when Priwall v3 is deployed — this is a mitigation, not a patch to the addon itself.

Discovered November 2025 and disclosed 13 August 2026 through INCD. Around 415 vulnerable instances were found online, 269 of them in Israel, many serving hundreds of downstream businesses. Roughly 2,278 accessible data sets were reachable, including financial records, customer data and user accounts.

Research by Roei Hadashi and Dean Bar at HackersEye.

read the full technical writeup on hackerseye.com →

## THE OTHER 8 CVES

← all 9 records · this record on cve.org