Home

Description

A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03. This affects an unknown function of the component JNLP Deployment Endpoint. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED Reserved 2026-05-09 | Published 2026-05-10 | Updated 2026-05-10 | Assigner VulDB




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X
MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:X
MEDIUM: 5.3CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:X
5.0AV:N/AC:L/Au:N/C:P/I:N/A:N/E:ND/RL:ND/RC:ND

Problem types

Use of Hard-coded Cryptographic Key

Key Management Error

Product status

8.03
affected

Timeline

2026-05-09:Advisory disclosed
2026-05-09:VulDB entry created
2026-05-09:VulDB entry last update

Credits

b1lal (VulDB User) reporter

VulDB CNA Team coordinator

References

vuldb.com/vuln/362459 (VDB-362459 | Industrial Application Software IAS Canias ERP JNLP Deployment Endpoint hard-coded key) vdb-entry

vuldb.com/vuln/362459/cti (VDB-362459 | CTI Indicators (IOB, IOC, TTP)) signature permissions-required

vuldb.com/submit/808296 (Submit #808296 | Industrial Application Software - IAS Canias ERP 8.03-- Use of Hard-coded Cryptographic Key (CWE-321)) third-party-advisory

cve.org (CVE-2026-8243)

nvd.nist.gov (CVE-2026-8243)

Download JSON