CVE-2026-84149

Published Sep 1, 2026

Last updated 2 days ago

CVSS critical 9.2
Git
ERP System

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-84149 is an information disclosure vulnerability found in the Manacle Technologies Multi-tenant ERP System. This flaw stems from a publicly accessible `.git` directory located on the application's web server. An unauthenticated, remote attacker can exploit this vulnerability by accessing the exposed `.git` directory. This allows them to browse or download the repository metadata, which can then be used to reconstruct parts of the application's source code. Such an exposure could potentially reveal sensitive data, including embedded credentials, API keys, and internal application logic. The vulnerability is categorized under CWE-527, which refers to the exposure of a version-control repository to an unauthorized control sphere.

Description
This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could exploit this vulnerability by accessing the exposed .git directory and retrieving repository metadata and associated files, which could allow reconstruction of the application's source code.
Source
vdisclose@cert-in.org.in
NVD status
Deferred

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.2
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

vdisclose@cert-in.org.in
CWE-527

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

26