Tag
Authorization Bypass in metasfresh DocumentAttachmentsRestController and CommentsRestController
1 TTPAuthenticated attackers can exploit improper record-level authorization checks in metasfresh ERP to perform unauthorized read, write, and delete operations on attachments and comments.
Path Traversal Vulnerability in AKINSOFT Wolvox9 ERP
1 TTP 1 CVEA path traversal vulnerability (CVE-2026-15585) in AKINSOFT Wolvox9 ERP KontrolPanel.exe versions s26.02.17 through s26.02.21 allows unauthenticated remote attackers to read arbitrary files from the host filesystem.
CVE-2026-14807: PROG MIS ERP App Hard-coded Credentials Vulnerability
3 TTPs 1 CVEAn unauthenticated remote attacker can exploit a Use of Hard-coded Credentials vulnerability (CWE-798) in the ERP App developed by PROG MIS, allowing the attacker to log in to view application code and obtain database account and password information, leading to high impact on confidentiality, integrity, and availability.
Canias ERP Authentication Bypass Vulnerability (CVE-2026-8216)
2 rules 1 TTP 1 CVECVE-2026-8216 is a remote improper authentication vulnerability in the iasServerRemoteInterface.doAction function of the Java RMI Session Management component of Industrial Application Software IAS Canias ERP 8.03.