PT-2026-107427 · Manacle Technologies · Multi-Tenant Erp System

CVE-2026-107103

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
This vulnerability exists in the ERP system due to insufficient validation and parameterization of user supplied input in an API endpoint. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted input to the vulnerable endpoint.
Successful exploitation of this vulnerability could allow the attacker to perform SQL injection attacks on the targeted system.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107103

Affected Products

Multi-Tenant Erp System