CVE-2026-8243
Deferred Deferred - Pending Action
Hard-Coded Cryptographic Key in IAS Canias ERP 8.03

Publication date: 2026-05-10

Last updated on: 2026-05-18

Assigner: VulDB

Description
A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03. This affects an unknown function of the component JNLP Deployment Endpoint. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-10
Last Modified
2026-05-18
Generated
2026-06-19
AI Q&A
2026-05-10
EPSS Evaluated
2026-06-18
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
industrial_application_software ias_canias_erp 8.03
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.
CWE-320 Key Management Errors
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the Industrial Application Software IAS Canias ERP version 8.03, specifically in an unknown function of the JNLP Deployment Endpoint component.

The issue involves the use of a hard-coded cryptographic key, which can be exploited remotely by an attacker through manipulation.

Impact Analysis

Exploitation of this vulnerability could allow an attacker to use a hard-coded cryptographic key, potentially compromising the security of encrypted communications or data within the affected software.

Since the attack can be performed remotely without any privileges or user interaction, it increases the risk of unauthorized access or data exposure.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8243. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart