CVE-2026-84148
Unauthenticated Information Disclosure via API in Unspecified ERP System
CVE-2026-84148 is a broken access control flaw (CWE-639, authorization bypass through a user-controlled key) in the API of an ERP system, assigned by India's CERT-In. An unauthenticated remote attacker can send requests to the affected API endpoint and manipulate a parameter, bypassing the improper authentication and authorization checks to retrieve sensitive information belonging to other users on the same system. The CVSS 4.0 score of 9.2 (critical) reflects high confidentiality impact on both the vulnerable system and any downstream data it exposes, with no privileges or user interaction required. Any organization running the affected ERP system is exposed, though the advisory does not name the vendor or version range. Exploitation has not been reported in the wild, there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS currently estimates only a 0.4% probability of exploitation within 30 days.
What to do: Watch for the CERT-In advisory or vendor bulletin that identifies the specific product and fixed versions, then patch promptly once released. In the meantime, restrict unauthenticated access to the ERP system's API endpoints (network filtering, allowlisting, or a WAF/virtual patch) and review API access logs for requests with manipulated user/record parameters indicating data access across accounts. If the affected product is confirmed, enumerate exposed users' data via the API to check for signs of prior information disclosure.
| ERP system (API endpoint) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manipulating parameter which could lead to exposure of sensitive information belonging to other users on the targeted system.
- Weakness
- CWE-639
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.