Improper Authentication in ERP System by Vendor
CVE-2026-84148
9.2CRITICAL
What is CVE-2026-84148?
A vulnerability exists in the ERP system due to inadequate authentication and authorization mechanisms in its API endpoint. This flaw allows unauthenticated remote attackers to manipulate parameters, potentially granting them access to sensitive information from other users within the system. This could lead to unauthorized disclosure of data, posing significant risks to user privacy and security.
Affected Version(s)
Multi-tenant ERP System version
References
CVSS V4
Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability is reported by Nisarga Adhikary.
