CVE 8.2 HIGH

WebErpMesv2 allows unauthenticated API Access_CVE-2026-22788

8.2 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Description

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, the WebErpMesV2 application exposes multiple sensitive API endpoints without authentication middleware. An unauthenticated remote attacker can read business-critical data including companies, quotes, orders, tasks, and whiteboards. Limited write access allows creation of company records and full manipulation of collaboration whiteboards. This vulnerability is fixed in 1.19.

Basic Information

ID CVE-2026-22788
Source GitHub_M
Published Jan 12, 2026 at 21:40
Modified Jan 12, 2026 at 21:48

Affected Product

Vendor SMEWebify
Product WebErpMesv2
Version < 1.19
Affected Versions SMEWebify WebErpMesv2 < 1.19

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.