Description
This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by uploading arbitrary files to a web accessible directory on the targeted system

Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code and compromise the targeted system.
Published: 2026-09-01
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Contact Vendor
AI Analysis

Impact

This vulnerability arises from improper authentication controls and insufficient file type validation at an API endpoint. An unauthenticated remote attacker can upload arbitrary files to a web‑accessible directory, enabling execution of arbitrary code and full compromise of the system.

Affected Systems

The flaw affects the Manacle Technologies Multi‑tenant ERP System. No specific version information is available; the vulnerability applies to the system as a whole across all installations.

Risk and Exploitability

The CVSS score of 10 indicates critical severity, and the EPSS score is unavailable. The vulnerability is not listed in the official KEV catalog. An attacker can exploit it remotely without authentication by posting a malicious file through the affected API. The combination of high impact and ease of exploitation results in a very high risk posture for organizations still running the vulnerable ERP.

Generated by OpenCVE AI on September 1, 2026 at 13:38 UTC.

Remediation

Vendor Solution

Contact the vendor for the patched version.


OpenCVE Recommended Actions

  • Contact Manacle Technologies to obtain and deploy the vendor‑released patch for the Multi‑tenant ERP System.
  • Restrict file upload API to authenticated users only and enforce strict MIME type and file extension checks to prevent arbitrary file uploads.
  • Configure the web server to serve uploaded content from a directory outside the web root or implement access controls to block execution of uploaded files.

Generated by OpenCVE AI on September 1, 2026 at 13:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Manacle Technologies
Manacle Technologies multi-tenant Erp System
Vendors & Products Manacle Technologies
Manacle Technologies multi-tenant Erp System

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by uploading arbitrary files to a web accessible directory on the targeted system Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code and compromise the targeted system.
Title Remote Code Execution Vulnerability in Manacle Technologies ERP System
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Manacle Technologies Multi-tenant Erp System
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published:

Updated: 2026-09-01T15:38:06.159Z

Reserved: 2026-09-01T07:29:59.721Z

Link: CVE-2026-84147

cve-icon Vulnrichment

Updated: 2026-09-01T15:38:01.900Z

cve-icon NVD

Status : Deferred

Published: 2026-09-01T13:20:08.780

Modified: 2026-09-01T16:17:31.407

Link: CVE-2026-84147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:14:47Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type