CVE-2026-107104
Received Received - Intake

Unsafe Deserialization in ERP System

Vulnerability report for CVE-2026-107104, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Indian Computer Emergency Response Team (CERT-In)

Description

This vulnerability exists in the ERP system due to unsafe deserialization of user controlled data in the affected functionality. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted data to the vulnerable functionality of the targeted system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code, manipulate application data or perform other unintended actions on the targeted system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Manacle Technologies Multi-tenant ERP System version

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unsafe deserialization flaw in an ERP system. It allows unauthenticated remote attackers to send specially crafted data to execute arbitrary code, manipulate data, or perform unintended actions on the system.

Detection Guidance

Detecting unsafe deserialization vulnerabilities typically requires inspecting application logs for suspicious input patterns, monitoring network traffic for malformed data, and using static/dynamic analysis tools. Check ERP system logs for unexpected deserialization errors or unusual data formats. Use tools like Burp Suite or OWASP ZAP to intercept and analyze serialized data in transit.

Impact Analysis

Exploitation could lead to full system compromise, data theft, unauthorized modifications, or disruption of ERP services. Attackers may gain control over critical business operations or sensitive information.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and integrity. GDPR and HIPAA mandate secure handling of sensitive data; exploitation could result in unauthorized access, breaches, and non-compliance penalties.

Mitigation Strategies

Immediately apply patches or updates from the ERP vendor if available. Disable or restrict access to the vulnerable functionality until patched. Implement network segmentation to limit exposure. Monitor systems for signs of exploitation and review access logs for unauthorized activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107104. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart