Junglewise Threat Intelligence

CVE-2026-8243: IAS Canias ERP hard-coded cryptographic key in JNLP Deployment Endpoint

CVE-2026-8243 · Severity: medium · CVSS 5.3 · Published 2026-05-10

Technologies: Industrial Application Software (IAS) Canias ERP. Vendors: Industrial Application Software (IAS).

Executive brief

Industrial Application Software (IAS) Canias ERP, an enterprise resource planning platform used in manufacturing and industrial environments, contains a security flaw in its deployment component. The software uses a hard-coded cryptographic key, which could allow an unauthorized person to decrypt or manipulate sensitive communication. This vulnerability can be exploited remotely without any user interaction or login credentials.

Technical details

A vulnerability exists in the JNLP Deployment Endpoint of Industrial Application Software (IAS) Canias ERP 8.03 due to the use of a hard-coded cryptographic key (CWE-321). The JNLP (Java Web Start) file, which is served over plain HTTP without authentication, contains or references components that rely on static keys for cryptographic operations. A remote, unauthenticated attacker can exploit this to decrypt sensitive data or facilitate further attacks against the Java RMI interface. This flaw was discovered as part of a larger research effort into the product's RMI protocol and deployment mechanism. As of the advisory date, the vendor has not responded to disclosure attempts, and no patch is currently available.

Affected products

  • Industrial Application Software (IAS) Canias ERP 8.03

Timeline

  • 2025-04: other: Vulnerability research began
  • 2026-05-09: disclosed: Public disclosure by security researcher
  • 2026-05-10: advisory: CVE published and listed on NVD/VulDB

References

Related threats