{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-105621","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-10-05T16:27:00.107Z","datePublished":"2026-10-06T03:30:13.220Z","dateUpdated":"2026-10-06T13:18:10.266Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-10-06T03:30:13.220Z"},"title":"jishenghua jshERP Financial Receipt Update AccountHeadService.java updateAccountHeadAndDetail improper authorization","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-285","lang":"en","description":"Improper Authorization"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-266","lang":"en","description":"Incorrect Privilege Assignment"}]}],"affected":[{"vendor":"jishenghua","product":"jshERP","versions":[{"version":"3.0","status":"affected"},{"version":"3.1","status":"affected"},{"version":"3.2","status":"affected"},{"version":"3.3","status":"affected"},{"version":"3.4","status":"affected"},{"version":"3.5","status":"affected"}],"cpes":["cpe:2.3:a:jishenghua:jsherp:*:*:*:*:*:*:*:*"],"modules":["Financial Receipt Update Handler"]}],"descriptions":[{"lang":"en","value":"A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component Financial Receipt Update Handler. Performing a manipulation results in improper authorization. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":5.4,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":5.4,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":5.5,"vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:ND/RC:C"}}],"timeline":[{"time":"2026-10-05T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-10-05T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-10-05T18:32:04.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"cztang (VulDB User)","type":"reporter"},{"lang":"en","value":"VulDB CNA Team","type":"coordinator"}],"references":[{"url":"https://vuldb.com/vuln/413644","name":"VDB-413644 | jishenghua jshERP Financial Receipt Update AccountHeadService.java updateAccountHeadAndDetail improper authorization","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/413644/cti","name":"VDB-413644 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-105621","name":"CVE-2026-105621 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/989317","name":"Submit #989317 | jishenghua jshERP ad6cf886dd4e0676723060a25d361c703dc56bc0 Missing Authorization","tags":["third-party-advisory"]},{"url":"https://github.com/jishenghua/jshERP/issues/167","tags":["exploit","issue-tracking"]},{"url":"https://github.com/jishenghua/jshERP/","tags":["product"]}],"x_generator":["VulDB PVTS v202610"]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-10-06T13:15:00.738586Z","id":"CVE-2026-105621","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-10-06T13:18:10.266Z"}}]}}