CVE-2026-107104 PUBLISHED

Unsafe Deserialization Vulnerability in Manacle Technologies ERP System

Assigner: CERT-In
Reserved: 07.10.2026 Published: 07.10.2026 Updated: 07.10.2026

This vulnerability exists in the ERP system due to unsafe deserialization of user controlled data in the affected functionality. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted data to the vulnerable functionality of the targeted system.

Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code, manipulate application data or perform other unintended actions on the targeted system.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Manacle Technologies
Product Multi-tenant ERP System
Versions Default: unaffected
  • Version version is affected

Solutions

Contact Manacle Technologies for the patched version.

Credits

  • This vulnerability is reported by Nisarga Adhikary. finder

References

Problem Types

  • CWE-502 Deserialization of untrusted data CWE

Impacts

  • CAPEC-137 Parameter Injection