---
id: CVE-2026-107103
title: >-
  This vulnerability exists in the ERP system due to insufficient validation and
  parameterization of user supplied input in an API endpoint
summary: >-
  This vulnerability exists in the ERP system due to insufficient validation and
  parameterization of user supplied input in an API endpoint. An unauthenticated
  remote attacker could exploit this vulnerability by supplying specially
  crafted…
severity: critical
cvss: 9.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-89
vendor: Manacle Technologies
product: Multi-tenant ERP System
affected:
  - multi-tenant_erp_system version
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T09:17:04.913'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107103'
references:
  - url: >-
      https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0430
    label: vdisclose@cert-in.org.in
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-07T09:22:30.526Z'
---

## Overview

This vulnerability exists in the ERP system due to insufficient validation and parameterization of user supplied input in an API endpoint. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted input to the vulnerable endpoint.

Successful exploitation of this vulnerability could allow the attacker to perform SQL injection attacks on the targeted system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
