CVE-2026-8217Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in Industrial Application Software IAS Canias ERP 8.03. Impacted is the function Runtime.getRuntime.exec of the component RMI Interface. Performing a manipulation of the argument troiaCode results in os command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-10); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-10: 3Mentions · 2026-05-11: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-05-10: 3Technical Details · 2026-05-11: 105-1005-11
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-103
Disclosure3
2026-05-111
Patch1
Full discourse4 posts
  • Vladimir Cageyv Samoylov@cageyvdev
    Patch

    🚨 New CVEs w/ exploits: osTicket CSRF (CVE-2026-8194), Canias ERP RCE (CVE-2026-8217), GDAL overflow & more. Linux 'Dirty Frag' LPE chain for root (CVE-2026-43284/43500). HN buzz: AI fatigue, cloud costs, local AI. Patch fast! Simplify stacks. #infosec #Linux

    Post summary

    The tweet reports several newly disclosed CVEs with known exploits and urges immediate patching, highlighting the need to secure affected systems.

    0000057
    27 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-8217 A security flaw has been discovered in Industrial Application Software IAS Canias ERP 8.03. Impacted is the function Runtime.getRuntime.exec of the component RMI Interf… https://www.cve.org/CVERecord?id=CVE-2026-8217 ----- Traducción: CVE-2026-8217 Se … http://infoflow.cloud`

    Post summary

    The post announces the discovery of CVE-2026-8217 in IAS Canias ERP 8.03, describing the affected component but providing no exploitation or remediation details.

    0000022
    76 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8217 A security flaw has been discovered in Industrial Application Software IAS Canias ERP 8.03. Impacted is the function Runtime.getRuntime.exec of the component RMI Interf… https://www.cve.org/CVERecord?id=CVE-2026-8217

    Post summary

    An industrial ERP system vulnerability affecting Runtime.getRuntime.exec was disclosed, with no further details on PoC, exploit, or remediation provided.

    00000135
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8217 Remote Code Execution in Industrial Application Software IAS Canias ERP 8.03 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8217

    Post summary

    A new remote code execution vulnerability (CVE-2026-8217) has been disclosed for IAS Canias ERP 8.03, with details posted on Vulmon, but no PoC, exploit tool, or active exploitation evidence is provided.

    0000058
    4.0K followersView on X

Explore more