{"id":"CVE-2026-107103","title":"This vulnerability exists in the ERP system due to insufficient validation and parameterization of user supplied input in an API endpoint","summary":"This vulnerability exists in the ERP system due to insufficient validation and parameterization of user supplied input in an API endpoint. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted…","severity":"critical","cvss":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-89"],"vendor":"Manacle Technologies","product":"Multi-tenant ERP System","affected":["multi-tenant_erp_system version"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T09:17:04.913","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107103","references":[{"url":"https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0430","label":"vdisclose@cert-in.org.in"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-07T09:22:30.526Z","slug":"CVE-2026-107103","body":"## Overview\n\nThis vulnerability exists in the ERP system due to insufficient validation and parameterization of user supplied input in an API endpoint. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted input to the vulnerable endpoint.\n\nSuccessful exploitation of this vulnerability could allow the attacker to perform SQL injection attacks on the targeted system.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":51,"depthScoreParts":{"impact":51.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}