Description
This vulnerability exists in the ERP system due to unsafe deserialization of user controlled data in the affected functionality. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted data to the vulnerable functionality of the targeted system.

Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code, manipulate application data or perform other unintended actions on the targeted system.
Published: 2026-10-07
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Contact Manacle Technologies for the patched version.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 08:45:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in the ERP system due to unsafe deserialization of user controlled data in the affected functionality. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted data to the vulnerable functionality of the targeted system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code, manipulate application data or perform other unintended actions on the targeted system.
Title Unsafe Deserialization Vulnerability in Manacle Technologies ERP System
First Time appeared Manacle Technologies
Manacle Technologies multi-tenant Erp System
Weaknesses CWE-502
CPEs cpe:2.3:a:manacle_technologies:multi-tenant_erp_system:version:*:*:*:*:*:*:*
Vendors & Products Manacle Technologies
Manacle Technologies multi-tenant Erp System
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Manacle Technologies Multi-tenant Erp System
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published:

Updated: 2026-10-07T08:25:14.500Z

Reserved: 2026-10-07T06:16:49.039Z

Link: CVE-2026-107104

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data