CVE-2026-84149CWE-527

CVE-2026-84149

published September 1, 2026

CVSS
9.2
EPSS
0%
Percentile
24.8
In the wild
Unconfirmed
What it is

This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could exploit this vulnerability by accessing the exposed .git directory and retrieving repository metadata and associated files, which could allow reconstruction of the application's source code.

The record
Technical detail
CVSS
9.2 · NONE
CVSS v4.0
9.2 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
EPSS
0.00322 · 24.8th percentile
Weakness
CWE-527 · Exposure of Version-Control Repository to an Unauthorized Control Sphere
Published
2026-09-01T17:20Z
References (1)
EPSS history
Timeline
  • 03 SEP 03:32Z
    EPSS moved — → 0%
    epss
  • 01 SEP 12:44Z
    Information Disclosure Vulnerability in Manacle Technologies ERP System
    cvelistv5