Ghostwire

CVE-2026-94413: jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve...

HIGH CVSS 0.0 EPSS 0.31%

Published: September 21, 2026 | Last Modified: September 21, 2026

Description

jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsalted MD5 password digests for any user. Attackers can request arbitrary user information by supplying user IDs to obtain password hashes usable for offline cracking or direct authentication bypass.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.31% (24th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References