
[CIVN-2026-0430] Multiple Vulnerabilities in Manacle Technologies ERP System
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Manacle Technologies ERP System
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Systems Affected
Manacle Technologies Multi-tenant ERP System
Overview
Multiple vulnerabilities have been reported in Manacle Technologies ERP system, which could allow a remote attacker to execute arbitrary code and gain unauthorized access to sensitive information on the targeted system.
Target Audience:
Organizations, system administrators and maintainers of the affected application.
Risk Assessment:
Risk of remote code execution, unauthorized access to sensitive information and application source code.
Impact Assessment:
Potential for arbitrary code execution, enumerate user records and .git directory exposure.
Description
Manacle Technologies Multi-tenant Enterprise Resource Planning (ERP) system is a centralized enterprise resource planning platform that supports multiple organizations within a shared system environment to manage core business processes, while keeping each tenant¿s data and configurations separate.
1. Remote Code Execution Vulnerability ( CVE-2026-84147 )
This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by uploading arbitrary files to a web accessible directory on the targeted system.
Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code and compromise the targeted system.
2. Insecure Direct Object Reference Vulnerability ( CVE-2026-84148 )
This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manipulating parameter which could lead to exposure of sensitive information belonging to other users on the targeted system.
3. Information Disclosure Vulnerability ( CVE-2026-84149 )
This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could exploit this vulnerability by accessing the exposed .git directory and retrieving repository metadata and associated files, which could allow reconstruction of the applications source code.
Credit
These vulnerabilities are reported by Nisarga Adhikary.
Solution
Contact the vendor for the patched version.
Vendor Information
Manacle Technologies
https://www.manacle.in/erp
References
Manacle Technologies
https://www.manacle.in/erp
CVE Name
CVE-2026-84147
CVE-2026-84148
CVE-2026-84149
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqW4g8ACgkQ3jCgcSdc
ys/AchAAlQ7bsAQEepsX5ws6drkT+o62+4pCF9WXs9W/AHUr0eA4Y21o15nPr/ws
ZY88Zgq6jSXKDZWQZHjUUYUsVlaPWECuJbysempl1Hu6LcIih2zUiw2WfBgGCuNV
nIeR2lLxoYBvu+xanqOeL0WsHrwrvNIW3rbP1fZp0DGlFoWB9657uPXKZykQ+O8Q
4lXPLlml0rRYJigOwegmXGG1UkOXv3tscBriBOa0HuCAVDjvT3ClfXxi0BrF1SRX
3S/G7EL6TxH+IwZBfqe8C6WhzBkp7YBz4kmCX5ciFUXCxI8ng79kGfcFai2JQWtG
lLq6PoopoR3YXp63h7YyckrEjIb78yVZPGguWM/GY8XC4kfBTifyK8k5SF7igjpf
ZXBWPrLXjHij9Z9nVn7B1dG375c2oO1HweJtH3y6mAjCj66CQLjfN+R/RPKPb2gh
rPqOkD2A53X6gNDlPyXdq7SdNbHozfKayR73JFwkUh4mFtblO+aCXLG4L5h0myz3
6YDr39EMhmVwAuBnpQMwwnaoADM5vi1vepuWgs71MV7ShXZq6Qiq6tK8yESUxqdL
BrPyoukBo89Hd+JxPOhC6N8kEy0Q/sD7D4lmHRxqErt7Bm+SY8ofJ/wGklikHz2C
g6hGI+GsxziNxOYW/3QJLapmQ+vKS0uWdynwAQlsnkBjfDThRLo=
=8bXG
—–END PGP SIGNATURE—–


