Junglewise Threat Intelligence

CVE-2026-8244: IAS Canias ERP improper authentication in Login RMI Interface

CVE-2026-8244 · Severity: medium · CVSS 5.3 · Published 2026-05-10

Technologies: Industrial Application Software (IAS) Canias ERP. Vendors: Industrial Application Software (IAS).

Executive brief

A vulnerability exists in the login interface of Canias ERP, a software suite used for managing industrial and manufacturing business processes. By manipulating specific version parameters during the login process, an attacker can bypass standard authentication checks to obtain valid session identifiers. This allows an unauthorized user to gain a foothold in the system, which can be used to access sensitive business data or as a starting point for further attacks on the server.

Technical details

An improper authentication vulnerability (CWE-287) exists in the Login RMI Interface of IAS Canias ERP 8.03. The vulnerability is located in the handling of the 'clientVersion' argument within the RMI 'doAction' method. A remote, unauthenticated attacker can manipulate this argument to bypass authentication logic and disclose valid session IDs. These session IDs can subsequently be used to hijack active user or system sessions (such as CRONJOB sessions), facilitating further exploitation including remote code execution when chained with other vulnerabilities in the same product. As of the advisory date, the vendor has not provided a patch.

Affected products

  • Industrial Application Software (IAS) Canias ERP 8.03

Timeline

  • 2025-04: other: Vulnerability research began
  • 2026-05-09: disclosed: Public disclosure by security researcher
  • 2026-05-10: advisory: CVE published

References

Related threats