CVE-2026-84149

This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could exploit this vulnerability by accessing the exposed .git directory and retrieving repository metadata and associated files, which could allow reconstruction of the application's source code.

  • Published Sep 1, 2026
  • CVSS 9.2 critical
  • 0.5% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-84149 at the National Vulnerability Database