OS Command Injection Vulnerability in IAS Canias ERP by Industrial Application Software
CVE-2026-8217
Key Information:
- Status
- Vendor
- CVE Published:
- 10 May 2026
Badges
What is CVE-2026-8217?
A security flaw has been identified in IAS Canias ERP 8.03, specifically within the Runtime.getRuntime.exec function of the RMI Interface component. This vulnerability allows for OS command injection through the manipulation of the troiaCode argument, enabling potential remote exploitation. The implications of this flaw could lead to unauthorized execution of commands on the server. Despite early disclosure attempts to the vendor, there has been no response, putting users at significant risk from possible attacks leveraging this publicly released exploit.
Affected Version(s)
Canias ERP 8.03
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
