Skip to content
Threat Feed

Tag

Erp

4 briefs RSS
high advisory

Authorization Bypass in metasfresh DocumentAttachmentsRestController and CommentsRestController

Authenticated attackers can exploit improper record-level authorization checks in metasfresh ERP to perform unauthorized read, write, and delete operations on attachments and comments.

metasfresh ERP web-application-vulnerability authorization-bypass erp
1t
high advisory

Path Traversal Vulnerability in AKINSOFT Wolvox9 ERP

A path traversal vulnerability (CVE-2026-15585) in AKINSOFT Wolvox9 ERP KontrolPanel.exe versions s26.02.17 through s26.02.21 allows unauthenticated remote attackers to read arbitrary files from the host filesystem.

AKINSOFT Wolvox9 ERP vulnerability path-traversal erp
1t 1c
critical advisory

CVE-2026-14807: PROG MIS ERP App Hard-coded Credentials Vulnerability

An unauthenticated remote attacker can exploit a Use of Hard-coded Credentials vulnerability (CWE-798) in the ERP App developed by PROG MIS, allowing the attacker to log in to view application code and obtain database account and password information, leading to high impact on confidentiality, integrity, and availability.

ERP App hard-coded-credentials erp web-application vulnerability
3t 1c
high advisory

Canias ERP Authentication Bypass Vulnerability (CVE-2026-8216)

CVE-2026-8216 is a remote improper authentication vulnerability in the iasServerRemoteInterface.doAction function of the Java RMI Session Management component of Industrial Application Software IAS Canias ERP 8.03.

Canias ERP 8.03 cve authentication-bypass erp
2r 1t 1c