Authentication Bypass in ERP System by Affected Vendor
CVE-2026-107102

9.3CRITICAL

Key Information:

Vendor
CVE Published:
7 October 2026

What is CVE-2026-107102?

This vulnerability in the ERP system arises from inadequate validation of payment callback parameters combined with insufficient authentication controls in the API endpoint. An attacker with no authentication credentials can exploit this weakness by manipulating parameters, potentially causing the ERP application to create an authenticated session for any user without proper payment verification. If successfully executed, this could enable attackers to bypass standard authentication mechanisms, granting them unauthorized access to the accounts of legitimate users within the affected system.

Affected Version(s)

Multi-tenant ERP System version

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability is reported by Nisarga Adhikary.
.