CVE-2026-84147

Published Sep 1, 2026

Last updated 12 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-84147 is a vulnerability identified within an Enterprise Resource Planning (ERP) system. This flaw stems from improper authentication controls and insufficient file type validation at an API endpoint. An unauthenticated remote attacker could exploit this vulnerability. Successful exploitation could potentially allow the attacker to execute arbitrary code and compromise the target system.

Description
This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by uploading arbitrary files to a web accessible directory on the targeted system Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code and compromise the targeted system.
Source
vdisclose@cert-in.org.in
NVD status
Deferred

Risk scores

CVSS 4.0

Type
Secondary
Base score
10
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

vdisclose@cert-in.org.in
CWE-434

Social media

Hype score
Not currently trending