CVE-2026-84148: Insecure Direct Object Reference Vulnerability in Manacle Technologies ERP System
Published Sep 1, 2026
·Updated
This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manipulating parameter which could lead to exposure of sensitive information belonging to other users on the targeted system.
Affected Software
1 affected component
Manacle Technologies ERP System
Event History
Sep 1, 2026
CVE Published
via MITRE·12:38 PM
Data Sourced
via MITRE·12:38 PM
RemedyDescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated remote attacker could exploit the affected API endpoint. No valid user account is described as being required.
2
What does exploitation require?
The attacker would need to manipulate a parameter sent to the vulnerable API endpoint. The issue is attributed to improper authentication and authorization controls.
3
What is the potential impact?
Successful exploitation could expose sensitive information belonging to other users of the targeted ERP system.