CVE-2026-84148
Manacle Technologies · Multi-tenant ERP System
An improper authentication and authorization flaw in the API endpoint of the Manacle Technologies Multi-tenant ERP System allows unauthenticated attackers to expose sensitive user information.
Executive summary
A critical authentication and authorization bypass vulnerability in the Manacle Technologies Multi-tenant ERP System allows unauthenticated remote attackers to exfiltrate sensitive data.
Vulnerability
This vulnerability is an authorization bypass (CWE-639) caused by improper authentication and authorization controls in the system API. An unauthenticated remote attacker can manipulate parameters to access sensitive information belonging to other users.
Business impact
The vulnerability carries a CVSS score of 9.2, indicating a critical risk to data confidentiality. Successful exploitation could result in the unauthorized exposure of proprietary business data and customer information, leading to severe reputational damage, regulatory non-compliance, and potential loss of competitive advantage.
Remediation
Immediate Action: Contact Manacle Technologies support immediately to obtain the appropriate security patch or version update.
Proactive Monitoring: Monitor API access logs for unusual patterns or unauthorized requests targeting ERP endpoints.
Compensating Controls: Implement strict network access controls and utilize a Web Application Firewall (WAF) to filter malicious requests directed at the ERP API.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical CVSS severity and the ease of remote exploitation, organizations should prioritize contacting the vendor for remediation guidance. Immediate verification of API access controls and auditing of existing user permissions is recommended to minimize the impact of potential unauthorized access.
Sources
Originally found and disclosed by This vulnerability is reported by Nisarga Adhikary., per the CVE Program record.