Unauthorized Access in ERP System Due to Exposed Git Directory
CVE-2026-84149

9.2CRITICAL

Key Information:

Vendor
CVE Published:
1 September 2026

What is CVE-2026-84149?

This vulnerability affects an ERP system due to the exposure of sensitive repository information through an unintentionally accessible .git directory. An unauthenticated attacker can potentially exploit this flaw by gaining access to the exposed .git directory, which contains crucial metadata and files. This exposure may enable the reconstruction of the application’s source code, posing substantial risks to the integrity and security of the affected system.

Affected Version(s)

Multi-tenant ERP System version

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability is reported by Nisarga Adhikary.
.