# CVE-2026-84148

## Summary

- **CVE ID:** CVE-2026-84148
- **Severity:** CRITICAL
- **CVSS Score:** 9.2 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N)
- **CWE:** CWE-639
- **Published:** Sep 1, 2026
- **Last Modified:** Sep 1, 2026

## Description

This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manipulating parameter which could lead to exposure of sensitive information belonging to other users on the targeted system.

## Affected Products

- Manacle Technologies — Multi-tenant ERP System (version)

## References

- [CNA](https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0430)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.39%
- **EPSS Percentile:** 32.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._