This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manipulating parameter which could lead to exposure of sensitive information belonging to other users on the targeted system.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
Contact the vendor for the patched version.
Workaround
No workaround given by the vendor.
References
History
Tue, 01 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Manacle Technologies
Manacle Technologies multi-tenant Erp System |
|
| Vendors & Products |
Manacle Technologies
Manacle Technologies multi-tenant Erp System |
Tue, 01 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manipulating parameter which could lead to exposure of sensitive information belonging to other users on the targeted system. | |
| Title | Insecure Direct Object Reference Vulnerability in Manacle Technologies ERP System | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-In
Published:
Updated: 2026-09-01T15:39:38.556Z
Reserved: 2026-09-01T07:29:59.722Z
Link: CVE-2026-84148
No data.
Status : Deferred
Published: 2026-09-01T13:20:08.923
Modified: 2026-09-01T16:17:31.830
Link: CVE-2026-84148
No data.
OpenCVE Enrichment
Updated: 2026-09-01T14:14:45Z
Weaknesses