Improper Authentication and File Validation Flaw in Popular ERP System
CVE-2026-84147

10CRITICAL

Key Information:

Vendor
CVE Published:
1 September 2026

What is CVE-2026-84147?

This vulnerability stems from inadequate authentication controls and insufficient file type validation on the API endpoint of the ERP system. An unauthenticated attacker can exploit this flaw to upload arbitrary files to a web-accessible directory, potentially leading to arbitrary code execution and compromising the affected system. This issue highlights the critical need for robust security measures to safeguard against unauthorized access and ensure the integrity of systems relying on secure API configurations.

Affected Version(s)

Multi-tenant ERP System version

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability is reported by Nisarga Adhikary.
.