Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code and compromise the targeted system.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Contact the vendor for the patched version.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 01 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Manacle Technologies
Manacle Technologies multi-tenant Erp System |
|
| Vendors & Products |
Manacle Technologies
Manacle Technologies multi-tenant Erp System |
Tue, 01 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by uploading arbitrary files to a web accessible directory on the targeted system Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code and compromise the targeted system. | |
| Title | Remote Code Execution Vulnerability in Manacle Technologies ERP System | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-In
Published:
Updated: 2026-09-01T15:38:06.159Z
Reserved: 2026-09-01T07:29:59.721Z
Link: CVE-2026-84147
No data.
Status : Deferred
Published: 2026-09-01T13:20:08.780
Modified: 2026-09-01T16:17:31.407
Link: CVE-2026-84147
No data.
OpenCVE Enrichment
Updated: 2026-09-01T14:14:47Z
-
CWE-434
Unrestricted Upload of File with Dangerous Type