Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages. Attackers can submit sequential message IDs to read, edit, delete, or pin messages from other departments or companies, and enumerate all notes in the system. | |
| Title | Aureus ERP before 1.5.0 Unscoped Message Access via ChatterPanel | |
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-22T15:24:13.836Z
Reserved: 2026-09-22T12:29:08.887Z
Link: CVE-2026-95655
No data.
Status : Received
Published: 2026-09-22T16:18:18.943
Modified: 2026-09-22T16:18:18.943
Link: CVE-2026-95655
No data.
OpenCVE Enrichment
No data.