CVE-2026-8024 Details
Description
A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.
A deserialization vulnerability allowing remote code execution has been identified in ibaPDA versions 1.0.0 prior to 8.14.0 and in ibaDatCoordinator versions 1.0.0 prior to 4.0.7. This vulnerability arises because the applications do not properly restrict the .NET BinaryFormatter when deserializing client-server input, potentially leading to type confusion and the execution of arbitrary code within the affected applications. Exploitation of this vulnerability occurs remotely and without authentication, allowing attackers to gain full access to the affected systems.
Users can update to ibaPDA version 8.14.0 or ibaDatCoordinator version 4.0.7. For ibaPDA, it is also recommended to restrict connections to localhost and manage Windows Firewall rules to deactivate incoming connections for the ibaPDA Client and Server. Similar firewall management is advised for ibaDatCoordinator.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 18, 2026CISA-ADP
Assessed Jun 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://certvde.com/en/advisories/VDE-2026-051 | [email protected] | AdvisoryRemedy |
| https://iba.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-051.json | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| iba AG ibaDatCoordinator | >= 1.0.0, < 4.0.7 (semver) |
CPE
Remediation
| |
| iba AG ibaPDA | >= 1.0.0, < 8.14.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 18, 2026 | New CVE Received | [email protected] |
| Jun 18, 2026 | CVE Modified | CISA-ADP |
Volerion