PULSE
FEED
ransomqilin reclama a CORBY ROCK MILL · IE · Manufacturingransomqilin reclama a Delta Marine · FI · Transportationransomqilin reclama a J&D Financial · Financial Servicesransomendzone reclama a Philander Smith University · US · Educationransomsilentransomgroup reclama a A...n · Not Foundransomnetrunner reclama a M** A******* G********** O******* a** P***** S****** A********* · US · Not Foundransomqilin reclama a Global Security Concepts · US · Professional Servicesransombyod reclama a Standpointe / Trinite Solutions · Professional Servicesransomsafepay reclama a dd-automation.ch · CZ · Technologyransomsafepay reclama a stuecheli.ch · CH · Retail & E-Commerceransomsafepay reclama a bwi-bau.de · DE · Professional Servicesransomsafepay reclama a halservice.it · IT · Professional Servicesransomsafepay reclama a grundens.com · US · Retail & E-Commerceransomsafepay reclama a t-systems.com · DE · Technologyransomqilin reclama a CORBY ROCK MILL · IE · Manufacturingransomqilin reclama a Delta Marine · FI · Transportationransomqilin reclama a J&D Financial · Financial Servicesransomendzone reclama a Philander Smith University · US · Educationransomsilentransomgroup reclama a A...n · Not Foundransomnetrunner reclama a M** A******* G********** O******* a** P***** S****** A********* · US · Not Foundransomqilin reclama a Global Security Concepts · US · Professional Servicesransombyod reclama a Standpointe / Trinite Solutions · Professional Servicesransomsafepay reclama a dd-automation.ch · CZ · Technologyransomsafepay reclama a stuecheli.ch · CH · Retail & E-Commerceransomsafepay reclama a bwi-bau.de · DE · Professional Servicesransomsafepay reclama a halservice.it · IT · Professional Servicesransomsafepay reclama a grundens.com · US · Retail & E-Commerceransomsafepay reclama a t-systems.com · DE · Technology
← All CVEs
CVE WatchOct 6, 2026

CVE-2026-105621

A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-b

CVSS

5.4

Medium

EPSS

—

KEV

—

Exploit Today

—

0-100

Published: Oct 6, 2026 · Last modified: Oct 6, 2026 · CWE-266 · CWE-285

EPSS · 30d

Not enough EPSS history yet.

Technical description

A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component Financial Receipt Update Handler. Performing a manipulation results in improper authorization. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-955948.1 HIG
—
———Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 4.0.0 versions.6h
CVE-2026-481977.2 HIG
—
———Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0.6h
CVE-2026-397758.8 HIG
—
———Subscriber Privilege Escalation in JobZilla - Job Board WordPress Theme <= 2.2 versions.6h
CVE-2026-397748.8 HIG
—
———Unauthenticated Privilege Escalation in Tourfic Pro <= 1.17.3 versions.6h
CVE-2026-3977310.0 CRI
—
———Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions.6h
CVE-2026-397657.2 HIG
—
———Shop Manager Privilege Escalation in Challan <= 3.7.88 versions.6h