Junglewise Threat Intelligence

CVE-2026-84148: Manacle Technologies ERP insecure direct object reference in API endpoint

CVE-2026-84148 · Severity: info · CVSS 7.5 · Published 2026-09-01

Technologies: Manacle Technologies Multi-tenant ERP System. Vendors: Manacle Technologies.

Executive brief

Manacle Technologies' multi-tenant ERP system, used by organizations to manage core business processes across multiple tenants, contains an authentication bypass vulnerability in its API endpoint. An unauthenticated attacker can manipulate API parameters to access sensitive information belonging to other users or organizations, potentially exposing confidential business data, customer records, and financial information.

Technical details

This is an Insecure Direct Object Reference (IDOR) vulnerability caused by improper authentication and authorization controls in the ERP system's API endpoint. An unauthenticated remote attacker can exploit the vulnerability by manipulating request parameters to access data belonging to other users or tenants in the multi-tenant environment. No authentication or valid user credentials are required to exploit this flaw. Successful exploitation allows the attacker to enumerate and retrieve sensitive information from other organizations' records. Patch availability and remediation steps should be obtained from Manacle Technologies.

Affected products

  • Manacle Technologies Multi-tenant ERP System <UNKNOWN>

Timeline

  • 2026-09-01: disclosed: Vulnerability disclosed by CERT-In as part of multiple vulnerabilities in Manacle Technologies ERP system

References

Related threats