Executive brief
Manacle Technologies Multi-tenant ERP System is an enterprise resource planning platform used by organizations to manage core business processes across multiple tenants. An unauthenticated attacker can upload arbitrary files to a web-accessible directory due to missing authentication and file type validation, leading to remote code execution and full system compromise.
Technical details
CVE-2026-84147 is a remote code execution vulnerability in the ERP system's API endpoint caused by improper authentication controls and inadequate file type validation. An unauthenticated attacker can exploit this by uploading arbitrary files to a web-accessible directory on the targeted system. The vulnerability requires network access but no authentication or user interaction. Successful exploitation allows arbitrary code execution with the privileges of the web application, enabling complete system compromise. The vendor (Manacle Technologies) has been notified; contact them for patched versions.
Affected products
- Manacle Technologies Multi-tenant ERP System
Timeline
- 2026-09-01: disclosed