Authentication Bypass in ERP System by Affected Vendor
CVE-2026-107102
9.3CRITICAL
What is CVE-2026-107102?
This vulnerability in the ERP system arises from inadequate validation of payment callback parameters combined with insufficient authentication controls in the API endpoint. An attacker with no authentication credentials can exploit this weakness by manipulating parameters, potentially causing the ERP application to create an authenticated session for any user without proper payment verification. If successfully executed, this could enable attackers to bypass standard authentication mechanisms, granting them unauthorized access to the accounts of legitimate users within the affected system.
Affected Version(s)
Multi-tenant ERP System version
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability is reported by Nisarga Adhikary.
