HIGH 8.6 NVD
CVE-2026-95655
Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages. Attacke
Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages. Attackers can submit sequential message IDs to read, edit, delete, or pin messages from other departments or companies, and enumerate all notes in the system.
References
- https://github.com/aureuserp/aureuserp
- https://github.com/aureuserp/aureuserp/blob/v1.4.0/plugins/webkul/chatter/src/Livewire/Cha
- https://github.com/aureuserp/aureuserp/blob/v1.4.0/plugins/webkul/chatter/src/Livewire/Cha
- https://github.com/aureuserp/aureuserp/commit/d3d5ac20ec544e97636490db6f86a391c04ce899
- https://github.com/aureuserp/aureuserp/pull/1382
This high severity vulnerability with a CVSS score of 8.6 was published on 2026-09-22 via NVD.
vulnfeed aggregates 14151 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.