Unauthorized Access in ERP System Due to Exposed Git Directory
CVE-2026-84149
9.2CRITICAL
What is CVE-2026-84149?
This vulnerability affects an ERP system due to the exposure of sensitive repository information through an unintentionally accessible .git directory. An unauthenticated attacker can potentially exploit this flaw by gaining access to the exposed .git directory, which contains crucial metadata and files. This exposure may enable the reconstruction of the application’s source code, posing substantial risks to the integrity and security of the affected system.
Affected Version(s)
Multi-tenant ERP System version
References
CVSS V4
Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability is reported by Nisarga Adhikary.
