SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-84148

CRITICAL · CVSS 9.2 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The vulnerability in the ERP system arises from inadequate authentication and authorization controls in its API endpoint, allowing unauthenticated remote attackers to manipulate parameters. This exploitation could result in unauthorized access to sensitive information of other users within the system. Organizations utilizing this ERP system should prioritize remediation efforts due to the critical severity and potential data exposure risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84148
Severity
CRITICAL
CVSS
9.2
EPSS
0.39%

Original NVD Description

This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manipulating parameter which could lead to exposure of sensitive information belonging to other users on the targeted system.