CVE-2026-84147
Manacle Technologies · Multi-tenant ERP System
An unauthenticated remote code execution vulnerability in the Manacle Technologies Multi-tenant ERP System allows attackers to upload arbitrary files via the API endpoint.
Executive summary
A critical vulnerability in the Manacle Technologies Multi-tenant ERP System allows unauthenticated remote attackers to achieve full system compromise via arbitrary file uploads.
Vulnerability
This vulnerability, classified as CWE-434, stems from improper authentication controls and insufficient file type validation at the API endpoint. An unauthenticated attacker can leverage this flaw to upload malicious files to web accessible directories, facilitating remote code execution.
Business impact
The CVSS score of 10.0 reflects the maximum severity, as the vulnerability is remotely exploitable without authentication and results in total system compromise. Successful exploitation grants an attacker complete control over the ERP system, leading to unauthorized data access, potential data exfiltration of sensitive business information, and significant operational disruption.
Remediation
Immediate Action: Contact Manacle Technologies support immediately to obtain the necessary security update or patch for your environment.
Proactive Monitoring: Review web server logs for suspicious API requests and monitor file system activity for unexpected file creations in web directories.
Compensating Controls: Deploy a Web Application Firewall (WAF) with strict rules to block unauthorized file uploads and filter requests to the vulnerable API endpoint.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical severity of this vulnerability and the potential for total system compromise, organizations should prioritize remediation immediately. Engage the vendor to secure the appropriate update and ensure that all public-facing API endpoints are monitored for signs of unauthorized access until a patch is applied.
Sources
Originally found and disclosed by This vulnerability is reported by Nisarga Adhikary., per the CVE Program record.