Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-84147: Manacle ERP lets remote attacker run their own code
CVE-2026-84147 · published 2 days ago
Summary
The Manacle ERP system can be tricked by anyone on the internet into accepting files it shouldn’t. Because the system doesn’t properly check who is uploading files or what type they are, an attacker could place a malicious file on the server and cause it to run their code. Apply the vendor’s security update or block the vulnerable upload feature until it is fixed.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| manacle technologies | multi-tenant erp system | version |
Original advisory text
Remote Code Execution Vulnerability in Manacle Technologies ERP System
This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by uploading arbitrary files to a web accessible directory on the targeted system
Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code and compromise the targeted system.
Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code and compromise the targeted system.
Severity
10.0
Critical
CVSS 4.0: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published1 Sep 2026
Updated2 Sep 2026
First seen1 Sep 2026
Monitor software like this
Free during beta