---
cve: "CVE-2026-59499"
severity: "HIGH"
cvss: 8.6
epss: "32%"
vendor: "Priority"
kev: false
exploited: false
published: "2026-08-13 10:17:14"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-06T22:41:32+02:00"
---

# CVE-2026-59499

> 8.6 HIGH

## Beschreibung

: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions)..

This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions).: All versions without Priwall v3.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Schwachstellen-Klasse

- **CWE-200** — Exposure of Sensitive Information to an Unauthorized Actor
  The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

## Angriffsmuster (CAPEC)

- [CAPEC-13 — Subverting Environment Variable Values](https://capec.mitre.org/data/definitions/13.html) _(Severity: Very High)_
- [CAPEC-22 — Exploiting Trust in Client](https://capec.mitre.org/data/definitions/22.html) _(Severity: High)_
- [CAPEC-116 — Excavation](https://capec.mitre.org/data/definitions/116.html) _(Severity: Medium)_
- [CAPEC-169 — Footprinting](https://capec.mitre.org/data/definitions/169.html) _(Severity: Very Low)_
- [CAPEC-224 — Fingerprinting](https://capec.mitre.org/data/definitions/224.html) _(Severity: Very Low)_
- [CAPEC-285 — ICMP Echo Request Ping](https://capec.mitre.org/data/definitions/285.html) _(Severity: Low)_
- [CAPEC-287 — TCP SYN Scan](https://capec.mitre.org/data/definitions/287.html) _(Severity: Low)_
- [CAPEC-290 — Enumerate Mail Exchange (MX) Records](https://capec.mitre.org/data/definitions/290.html) _(Severity: Low)_

## ATT&CK-Techniken

- [T1562.003 — Impair Defenses:Impair Command History Logging](https://attack.mitre.org/techniques/T1562/003/)
- [T1574.006 — Hijack Execution Flow:Dynamic Linker Hijacking](https://attack.mitre.org/techniques/T1574/006/)
- [T1574.007 — Hijack Execution Flow:Path Interception by PATH Environment ](https://attack.mitre.org/techniques/T1574/007/)
- [T1217 — Browser Bookmark Discovery](https://attack.mitre.org/techniques/T1217/)
- [T1592 — Gather Victim Host Information](https://attack.mitre.org/techniques/T1592/)
- [T1595 — Active Scanning](https://attack.mitre.org/techniques/T1595/)

## Referenzen

- <https://www.gov.il/en/departments/dynamiccollectors/cve_advisories_listing?skip=0>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-59499) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
