PatchSiren

Manacle Technologies CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Manacle Technologies CVE published 2026-10-07

CVE-2026-107104

CVE-2026-107104 Unsafe Deserialization Vulnerability in Manacle Technologies ERP System. The ERP system is vulnerable to unsafe deserialization of user-controlled data, allowing an unauthenticated remote attacker to execute arbitrary code, manipulate application data, or perform other unintended actions. Defenders should assess exposure and prioritize remediation to prevent potential code execution, data [truncated]

CRITICAL Manacle Technologies CVE published 2026-10-07

CVE-2026-107103

CVE-2026-107103: A critical SQL injection vulnerability exists in the Manacle Technologies ERP System due to insufficient validation and parameterization of user-supplied input in an API endpoint. This vulnerability allows an unauthenticated remote attacker to exploit the system by supplying specially crafted input to the vulnerable endpoint, potentially leading to SQL injection attacks and unauthorized a [truncated]

CRITICAL Manacle Technologies CVE published 2026-10-07

CVE-2026-107102

CVE-2026-107102 Account Takeover Vulnerability in Manacle Technologies ERP System. The ERP system is vulnerable due to improper validation of payment callback parameters and inadequate authentication controls in API endpoints, allowing for account takeover and authentication bypass. Defenders should assess exposure and prioritize remediation to prevent potential unauthorized access and elevated privileges [truncated]