# CVE-2026-84149

## Summary

- **CVE ID:** CVE-2026-84149
- **Severity:** CRITICAL
- **CVSS Score:** 9.2 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N)
- **CWE:** CWE-527
- **Published:** Sep 1, 2026
- **Last Modified:** Sep 1, 2026

## Description

This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could exploit this vulnerability by accessing the exposed .git directory and retrieving repository metadata and associated files, which could allow reconstruction of the application's source code.

## Affected Products

- Manacle Technologies — Multi-tenant ERP System (version)

## References

- [CNA](https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0430)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.32%
- **EPSS Percentile:** 24.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._