ZeroHour

CVE-2026-84148

Unauthenticated Information Disclosure via API in Unspecified ERP System

CVSS 4.0
9.2 critical
EPSS
<1%p32
Published
()
Modified
AI analysis

CVE-2026-84148 is a broken access control flaw (CWE-639, authorization bypass through a user-controlled key) in the API of an ERP system, assigned by India's CERT-In. An unauthenticated remote attacker can send requests to the affected API endpoint and manipulate a parameter, bypassing the improper authentication and authorization checks to retrieve sensitive information belonging to other users on the same system. The CVSS 4.0 score of 9.2 (critical) reflects high confidentiality impact on both the vulnerable system and any downstream data it exposes, with no privileges or user interaction required. Any organization running the affected ERP system is exposed, though the advisory does not name the vendor or version range. Exploitation has not been reported in the wild, there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS currently estimates only a 0.4% probability of exploitation within 30 days.

What to do: Watch for the CERT-In advisory or vendor bulletin that identifies the specific product and fixed versions, then patch promptly once released. In the meantime, restrict unauthenticated access to the ERP system's API endpoints (network filtering, allowlisting, or a WAF/virtual patch) and review API access logs for requests with manipulated user/record parameters indicating data access across accounts. If the affected product is confirmed, enumerate exposed users' data via the API to check for signs of prior information disclosure.

Affected
ERP system (API endpoint)
Estimated exposure
unknown (affected product and its deployment footprint are not identified in the advisory) — The advisory does not name the ERP vendor, product, or install base, and ERP APIs of this kind are often deployed internally or behind access controls, so no defensible order-of-magnitude estimate can be made from public data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manipulating parameter which could lead to exposure of sensitive information belonging to other users on the targeted system.

Weakness
CWE-639
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.