Home

Description

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, the WebErpMesV2 application exposes multiple sensitive API endpoints without authentication middleware. An unauthenticated remote attacker can read business-critical data including companies, quotes, orders, tasks, and whiteboards. Limited write access allows creation of company records and full manipulation of collaboration whiteboards. This vulnerability is fixed in 1.19.

PUBLISHED Reserved 2026-01-09 | Published 2026-01-12 | Updated 2026-01-13 | Assigner GitHub_M




HIGH: 8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Problem types

CWE-306: Missing Authentication for Critical Function

Product status

< 1.19
affected

References

github.com/...pMesv2/security/advisories/GHSA-pp68-5pc2-hv7w exploit

github.com/...pMesv2/security/advisories/GHSA-pp68-5pc2-hv7w

github.com/...ommit/3a7ab1c95d1d1c8f7c62c84bc87b3666ecd2fa23

cve.org (CVE-2026-22788)

nvd.nist.gov (CVE-2026-22788)

Download JSON