Description
This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by uploading arbitrary files to a web accessible directory on the targeted system
Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code and compromise the targeted system.
Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code and compromise the targeted system.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Contact the vendor for the patched version.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 01 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by uploading arbitrary files to a web accessible directory on the targeted system Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code and compromise the targeted system. | |
| Title | Remote Code Execution Vulnerability in Manacle Technologies ERP System | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERT-In
Published:
Updated: 2026-09-01T12:32:59.881Z
Reserved: 2026-09-01T07:29:59.721Z
Link: CVE-2026-84147
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses