CVE-2026-84149

Summary

This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could exploit this vulnerability by accessing the exposed .git directory and retrieving repository metadata and associated files, which could allow reconstruction of the application's source code.

Affected Software

VendorProductVersion RangeStatus
Manacle TechnologiesMulti-tenant ERP Systemversionaffected

Weaknesses

  • CWE-527: CWE-527 Exposure of Version-Control repository to an unauthorized control sphere

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References