Improper Authentication in ERP System by Vendor
CVE-2026-84148

9.2CRITICAL

Key Information:

Vendor
CVE Published:
1 September 2026

What is CVE-2026-84148?

A vulnerability exists in the ERP system due to inadequate authentication and authorization mechanisms in its API endpoint. This flaw allows unauthenticated remote attackers to manipulate parameters, potentially granting them access to sensitive information from other users within the system. This could lead to unauthorized disclosure of data, posing significant risks to user privacy and security.

Affected Version(s)

Multi-tenant ERP System version

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability is reported by Nisarga Adhikary.
.