Remote Code Execution Vulnerability in ibaPDA and ibaDatCoordinator by IBA
CVE-2026-8024

9.3CRITICAL

Key Information:

Vendor

Iba

Vendor
CVE Published:
18 June 2026

What is CVE-2026-8024?

A remote, unauthenticated attacker can exploit a vulnerability in ibaPDA and ibaDatCoordinator that allows for the deserialization of untrusted data. This exploitation can lead to the attacker gaining unauthorized full access to affected systems, posing significant security risks for organizations using these products. It is crucial for users to implement necessary security measures to protect their systems from potential breaches.

Affected Version(s)

ibaDatCoordinator 1.0.0 < 4.0.7

ibaPDA 1.0.0 < 8.14.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Security Researchers from tenable
.