SQL Injection Vulnerability in ERP System by Vendor
CVE-2026-107103

9.3CRITICAL

Key Information:

Vendor
CVE Published:
7 October 2026

What is CVE-2026-107103?

This vulnerability in the ERP system arises from inadequate validation and parameterization of user-supplied input at a critical API endpoint. An attacker without authentication could exploit this flaw by sending specially crafted input to the vulnerable endpoint, potentially leading to SQL injection attacks. The consequences of such exploitation may include unauthorized access to database contents, manipulation of data, and the compromise of sensitive information within the system.

Affected Version(s)

Multi-tenant ERP System version

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability is reported by Nisarga Adhikary.
.