Improper Authentication and File Validation Flaw in Popular ERP System
CVE-2026-84147
10CRITICAL
What is CVE-2026-84147?
This vulnerability stems from inadequate authentication controls and insufficient file type validation on the API endpoint of the ERP system. An unauthenticated attacker can exploit this flaw to upload arbitrary files to a web-accessible directory, potentially leading to arbitrary code execution and compromising the affected system. This issue highlights the critical need for robust security measures to safeguard against unauthorized access and ensure the integrity of systems relying on secure API configurations.
Affected Version(s)
Multi-tenant ERP System version
References
CVSS V4
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability is reported by Nisarga Adhikary.
