CVE-2026-84147

Manacle Technologies · Multi-tenant ERP System

An unauthenticated remote code execution vulnerability in the Manacle Technologies Multi-tenant ERP System allows attackers to upload arbitrary files via the API endpoint.

Executive summary

A critical vulnerability in the Manacle Technologies Multi-tenant ERP System allows unauthenticated remote attackers to achieve full system compromise via arbitrary file uploads.

Vulnerability

This vulnerability, classified as CWE-434, stems from improper authentication controls and insufficient file type validation at the API endpoint. An unauthenticated attacker can leverage this flaw to upload malicious files to web accessible directories, facilitating remote code execution.

Business impact

The CVSS score of 10.0 reflects the maximum severity, as the vulnerability is remotely exploitable without authentication and results in total system compromise. Successful exploitation grants an attacker complete control over the ERP system, leading to unauthorized data access, potential data exfiltration of sensitive business information, and significant operational disruption.

Remediation

Immediate Action: Contact Manacle Technologies support immediately to obtain the necessary security update or patch for your environment.

Proactive Monitoring: Review web server logs for suspicious API requests and monitor file system activity for unexpected file creations in web directories.

Compensating Controls: Deploy a Web Application Firewall (WAF) with strict rules to block unauthorized file uploads and filter requests to the vulnerable API endpoint.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical severity of this vulnerability and the potential for total system compromise, organizations should prioritize remediation immediately. Engage the vendor to secure the appropriate update and ensure that all public-facing API endpoints are monitored for signs of unauthorized access until a patch is applied.

Sources

Originally found and disclosed by This vulnerability is reported by Nisarga Adhikary., per the CVE Program record.