Improper Authentication and File Validation Flaw in Popular ERP System
CVE-2026-84147
Key Information:
- Vendor
Manacle Technologies
- Status
- Vendor
- CVE Published:
- 1 September 2026
Badges
What is CVE-2026-84147?
CVE-2026-84147 identifies a significant vulnerability present in a widely-used ERP system developed by Manacle Technologies. This vulnerability stems from improper authentication mechanisms and insufficient validation of file types at an API endpoint. As a result, unauthenticated remote attackers can exploit this flaw by uploading arbitrary files to a publicly accessible directory on the targeted ERP system. If successfully executed, this could permit the attacker to run arbitrary code, leading to a complete compromise of the affected system. The repercussions of this vulnerability are severe, particularly for organizations that rely on this ERP software for their operations, as unauthorized access can result in loss of sensitive data, operational disruptions, and diminished trust from stakeholders.
Potential impact of CVE-2026-84147
-
Arbitrary Code Execution: The primary impact of this vulnerability is the potential for unauthorized execution of any code by an attacker. This capability can lead to total control of the compromised system, enabling the installation of malware, data exfiltration, or further intrusions into internal networks.
-
Data Breach Risks: Organizations can face significant risks related to data breaches, where sensitive information or proprietary business data may be exposed or stolen. Such breaches can have legal consequences, regulatory fines, and damage to reputation.
-
Operational Disruption: The exploitation of this vulnerability could lead to significant operational disruptions for organizations utilizing the ERP system. Attackers could cause downtime, hinder business processes, and potentially trigger financial losses due to inaccessibility of critical business functions.
Affected Version(s)
Multi-tenant ERP System version
References
CVSS V4
Timeline
- π
Vulnerability started trending
Vulnerability published
Vulnerability Reserved
