CVE-2026-8216
Received Received - Intake
Improper Authentication in IAS Canias ERP 8.03 via Java RMI

Publication date: 2026-05-10

Last updated on: 2026-05-10

Assigner: VulDB

Description
A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This issue affects the function iasServerRemoteInterface.doAction of the component Java RMI Session Management. Such manipulation leads to improper authentication. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-10
Last Modified
2026-05-10
Generated
2026-05-10
AI Q&A
2026-05-10
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
industrial_application_software canias_erp 8.03
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in the Industrial Application Software IAS Canias ERP version 8.03, specifically in the function iasServerRemoteInterface.doAction within the Java RMI Session Management component. It allows an attacker to manipulate the system in a way that leads to improper authentication. The attack can be performed remotely, meaning an attacker does not need physical access to exploit this issue.


How can this vulnerability impact me? :

The vulnerability can impact you by allowing unauthorized remote attackers to bypass authentication controls. This could lead to unauthorized access to the affected system, potentially compromising confidentiality, integrity, and availability of data and services within the IAS Canias ERP environment.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart