No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 22 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aureuserp
Aureuserp aureuserp |
|
| Vendors & Products |
Aureuserp
Aureuserp aureuserp |
Tue, 22 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages. Attackers can submit sequential message IDs to read, edit, delete, or pin messages from other departments or companies, and enumerate all notes in the system. | |
| Title | Aureus ERP before 1.5.0 Unscoped Message Access via ChatterPanel | |
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-22T17:44:08.806Z
Reserved: 2026-09-22T12:29:08.887Z
Link: CVE-2026-95655
Updated: 2026-09-22T17:22:46.197Z
Status : Received
Published: 2026-09-22T16:18:18.943
Modified: 2026-09-22T18:17:36.390
Link: CVE-2026-95655
No data.
OpenCVE Enrichment
Updated: 2026-09-22T17:30:18Z