Executive brief
Manacle Technologies' ERP system is widely deployed to manage core business processes across multiple organizations. A misconfiguration exposes the application's source code repository (.git directory) to the public internet, allowing attackers to download and reconstruct the entire codebase. This enables discovery of other hidden vulnerabilities, security bypasses, and business logic flaws that could be leveraged for further attacks.
Technical details
This is an information disclosure vulnerability (CWE-215) caused by an exposed .git directory accessible via HTTP/HTTPS without authentication. An unauthenticated remote attacker can download the entire Git repository metadata and associated source code files by making direct requests to the .git endpoint. The attack requires no special privileges, user interaction, or authentication. Successful exploitation allows reconstruction of application source code, which facilitates reconnaissance for other attacks (e.g., identifying credentials in code, finding API keys, discovering additional vulnerabilities). No patch availability is mentioned; vendor guidance suggests contacting Manacle Technologies for updates.
Affected products
- Manacle Technologies Multi-tenant ERP System <UNKNOWN>
Timeline
- 2026-09-01: disclosed