Junglewise Threat Intelligence

CVE-2026-8217: Industrial Application Software IAS Canias ERP OS command injection in RMI Interface

CVE-2026-8217 · Severity: medium · CVSS 6.3 · Published 2026-05-10

Technologies: Industrial Application Software (IAS) Canias ERP. Vendors: Industrial Application Software (IAS).

Executive brief

A security vulnerability exists in Canias ERP, a software suite used for managing industrial and manufacturing operations. An attacker can exploit this flaw to execute unauthorized commands on the server, potentially leading to a full system takeover or theft of sensitive business data. While the exploit requires an active session, researchers have demonstrated that sessions can be hijacked without any prior credentials, making this a high-risk issue for exposed servers.

Technical details

An OS command injection vulnerability exists in the RMI Interface of IAS Canias ERP 8.03. The root cause is the improper neutralization of special elements in the 'troiaCode' argument within the iasCtiRunCodeEvent function, which is subsequently passed to Runtime.getRuntime().exec(). While the CVSS vector indicates low privileges are required, researchers have demonstrated that an unauthenticated attacker can obtain a valid session ID by exploiting related vulnerabilities (CVE-2026-8214 and CVE-2026-8216) to hijack active sessions. Once a session is hijacked, the attacker can execute arbitrary OS commands with the privileges of the caniasERP service account. As of the advisory date, the vendor has not responded to disclosure attempts and no patch is available.

Affected products

  • Industrial Application Software IAS Canias ERP 8.03

Timeline

  • 2025-04: other: Vulnerability research began
  • 2026-05-09: disclosed: Public disclosure by HawkTrace researchers
  • 2026-05-10: advisory: NVD publication date

References