
[CIVN-2026-0429] Multiple Vulnerabilities in Manacle Technologies ERP System
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Manacle Technologies ERP System
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Systems Affected
Manacle Technologies Multi-tenant ERP System
Overview
Multiple vulnerabilities have been reported in Manacle Technologies ERP system, which could allow a remote attacker to execute arbitrary code and gain unauthorized access to sensitive information on the targeted system.
Target Audience:
Organizations, system administrators and maintainers of the affected application.
Risk Assessment:
Risk of remote code execution, unauthorized access to sensitive information and application source code.
Impact Assessment:
Potential for arbitrary code execution, enumerate user records and .git directory exposure.
Description
Manacle Technologies Multi-tenant Enterprise Resource Planning (ERP) system is a centralized enterprise resource planning platform that supports multiple organizations within a shared system environment to manage core business processes, while keeping each tenant¿s data and configurations separate.
1. Remote Code Execution Vulnerability ( CVE-2026-84147 )
This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by uploading arbitrary files to a web accessible directory on the targeted system.
Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code and compromise the targeted system.
2. Insecure Direct Object Reference Vulnerability ( CVE-2026-84148 )
This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manipulating parameter which could lead to exposure of sensitive information belonging to other users on the targeted system.
3. Information Disclosure Vulnerability ( CVE-2026-84149 )
This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could exploit this vulnerability by accessing the exposed .git directory and retrieving repository metadata and associated files, which could allow reconstruction of the applications source code.
Credit
These vulnerabilities are reported by Nisarga Adhikary.
Solution
Contact the vendor for the patched version.
Vendor Information
Manacle Technologies
https://www.manacle.in/erp
References
Manacle Technologies
https://www.manacle.in/erp
CVE Name
CVE-2026-84147
CVE-2026-84148
CVE-2026-84149
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqW4JQACgkQ3jCgcSdc
ys/7og/9GFbJfzDxkjR3BGqQI4iE2+e1R1kZmNXezO48d1gq7PCYlHuQOSznpPax
a19S+n0ZJbWbGrSoCN2IYAXoFU3EmkaKBu4iG2Hx2sKmbEvbICYQ77mAaxq0Yiza
3MjQPHk+7TEymobxcuzyily8fxbMeOGeRKxTPpZQU7WJlcgDmv3EbvqONvcZvKOT
UXr+msWaNKL38BO+9PNsdVMmbjvbDUlKXv0x8WXc43ET1RECLroLtFpMbJ7ox25U
VIPjKbRHVp9/xj1DXd1AGI3RHELkH01E6C9iq6ZRvXa0eLsK9Z2YkwqHQmcJ3+yL
YSDYrNM1uYrBHCSKnn+KKiDPQ2GG7D+1d8+YEW3/NSaAZE6o0adu8riHmHkjBXLP
1RozKDiJvVB7uNRsBaczOnV6cWzZ86z+ghQ6fk6urm5D0iMK7aT5oMpGyAPNP2r3
7sEwvp04+b7eppDpeC8j6MY1xKVwMI1GDRsNdiRqcjLjMRywIjBMQQoFcE0F+yLW
OoWqnRQGtvNW2mA/5hhtQZOgIK2ITPOKFHYUNpClNXijERZNTQPu9WEDF1l94AYX
urHZx105CXwj8oaclWBEMA41uiDTRSiff7putouFPolGbOC71siixpdaYiSExtpC
frizwyWtvOwwi7ZfqZN2s6sbRKluzTZ3uq5egRKzVQ5gHBPB6p8=
=9Uq2
—–END PGP SIGNATURE—–


