CERT-In Warns of Multiple High-Severity Flaws in Manacle Technologies ERP System
01 Sep, 2026 08:44 PM
India’s Computer Emergency Response Team (CERT-In) has reported multiple vulnerabilities in the Manacle Technologies Multi-tenant ERP System that could allow a remote attacker to execute arbitrary code and gain unauthorised access to sensitive information on a targeted system.
CERT-In issued Vulnerability Note CIVN-2026-0430 on September 1, 2026, assigning the vulnerabilities a HIGH severity rating.
The affected system is the Manacle Technologies Multi-tenant ERP System. The advisory is aimed at organisations, system administrators and maintainers of the affected application.
According to CERT-In, the risks include remote code execution, unauthorised access to sensitive information and application source code. The potential impact includes arbitrary code execution, enumeration of user records and exposure of the .git directory.
Manacle Technologies Multi-tenant Enterprise Resource Planning (ERP) system is a centralised enterprise resource planning platform that supports multiple organisations within a shared system environment to manage core business processes while keeping each tenant’s data and configurations separate.
Remote Code Execution Vulnerability — CVE-2026-84147
CERT-In said this vulnerability exists due to improper authentication controls and inadequate file type validation at the API endpoint.
An unauthenticated remote attacker could exploit the vulnerability by uploading arbitrary files to a web-accessible directory on the targeted system. Successful exploitation could allow the attacker to execute arbitrary code and compromise the targeted system.
Insecure Direct Object Reference Vulnerability — CVE-2026-84148
This vulnerability exists due to improper authentication and authorisation controls in the API endpoint.
An unauthenticated remote attacker could exploit the vulnerability by manipulating a parameter, which could lead to exposure of sensitive information belonging to other users on the targeted system.
Information Disclosure Vulnerability — CVE-2026-84149
The third vulnerability exists due to exposure of repository information through a publicly accessible .git directory.
An unauthenticated remote attacker could exploit the vulnerability by accessing the exposed .git directory and retrieving repository metadata and associated files. This could allow reconstruction of the application’s source code.
CERT-In said the vulnerabilities were reported by Nisarga Adhikary.
Solution
CERT-In has advised affected users to contact the vendor for the patched version.
Posted By: CYPEE Desk







