CVE-2026-27776
Received
Received - Intake
Insecure Deserialization in intra-mart IM-LogicDesigner Enables RCE
Publication date: 2026-02-27
Last updated on: 2026-03-23
Assigner: JPCERT/CC
Description
Description
IM-LogicDesigner module of intra-mart Accel Platform contains insecure deserialization issue. This can be exploited only when IM-LogicDesigner is deployed on the system. Arbitrary code may be executed when some crafted file is imported by a user with the administrative privilege.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| intra-mart | accel_platform | 8.0.16 |
| intra-mart | accel_platform | 8.0.17 |
| intra-mart | accel_platform | 8.0.19 |
| intra-mart | accel_platform | 8.0.20 |
| intra-mart | accel_platform | 8.0.21 |
| intra-mart | accel_platform | 8.0.22 |
| intra-mart | accel_platform | 8.0.23 |
| intra-mart | accel_platform | 8.0.24 |
| intra-mart | accel_platform | 8.0.25 |
| intra-mart | accel_platform | 8.0.26 |
| intra-mart | accel_platform | 8.0.27 |
| intra-mart | accel_platform | 8.0.10 |
| intra-mart | accel_platform | 8.0.11 |
| intra-mart | accel_platform | 8.0.12 |
| intra-mart | accel_platform | 8.0.13 |
| intra-mart | accel_platform | 8.0.14 |
| intra-mart | accel_platform | 8.0.15 |
| intra-mart | accel_platform | 8.0.4 |
| intra-mart | accel_platform | 8.0.5 |
| intra-mart | accel_platform | 8.0.6 |
| intra-mart | accel_platform | 8.0.7 |
| intra-mart | accel_platform | 8.0.8 |
| intra-mart | accel_platform | 8.0.9 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-502 | The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid. |