Improper Authentication and File Validation Flaw in Popular ERP System
CVE-2026-84147

10CRITICAL

Key Information:

Vendor
CVE Published:
1 September 2026

Badges

πŸ“ˆ TrendedπŸ“ˆ Score: 2,320

What is CVE-2026-84147?

CVE-2026-84147 identifies a significant vulnerability present in a widely-used ERP system developed by Manacle Technologies. This vulnerability stems from improper authentication mechanisms and insufficient validation of file types at an API endpoint. As a result, unauthenticated remote attackers can exploit this flaw by uploading arbitrary files to a publicly accessible directory on the targeted ERP system. If successfully executed, this could permit the attacker to run arbitrary code, leading to a complete compromise of the affected system. The repercussions of this vulnerability are severe, particularly for organizations that rely on this ERP software for their operations, as unauthorized access can result in loss of sensitive data, operational disruptions, and diminished trust from stakeholders.

Potential impact of CVE-2026-84147

  1. Arbitrary Code Execution: The primary impact of this vulnerability is the potential for unauthorized execution of any code by an attacker. This capability can lead to total control of the compromised system, enabling the installation of malware, data exfiltration, or further intrusions into internal networks.

  2. Data Breach Risks: Organizations can face significant risks related to data breaches, where sensitive information or proprietary business data may be exposed or stolen. Such breaches can have legal consequences, regulatory fines, and damage to reputation.

  3. Operational Disruption: The exploitation of this vulnerability could lead to significant operational disruptions for organizations utilizing the ERP system. Attackers could cause downtime, hinder business processes, and potentially trigger financial losses due to inaccessibility of critical business functions.

Affected Version(s)

Multi-tenant ERP System version

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • πŸ“ˆ

    Vulnerability started trending

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability is reported by Nisarga Adhikary.
.