| Publishing Date | 20.04.2026 |
|---|---|
| Last Update | 08.07.2026 |
| Tracking ID | IBA-2026-07 |
Summary
A vulnerability (CVE‑2026‑26171) was reported in a third‑party .NET library used by the ibaHD server that could allow an unauthenticated remote attacker to cause a denial of service through uncontrolled resource consumption when processing specially crafted XML data; no active exploitation of this vulnerability in the product is currently known.
Affected products
This applies to all iba products up to the versions listed below:
- ibaHD-Server v3.6.0
- ibaCMC v3.7.1
- ibaAnalyzer v8.3.5
- ibaDatCoordinator v4.1.0
How do I know that I’m affected?
If you have installed any of the products listed above, you are affected.
Solution
With the following versions, the issue has been fixed:
- ibaHD-Server v3.6.1
- ibaCMC v3.7.2
- ibaAnalyzer v8.4.0
- ibaDatCoordinator v4.1.1
Customer Actions
Please install the update as described in the solution.
Timeline
| 2026-04-16 | Noted by the Security Team |
| 2026-04-20 | Solution for the Problem in Version ibaHD-Server v3.6.1 |
| 2026-05-06 | Solution implement in ibaCMC v3.7.2 |
| 2026-06-06 | Solution implement in ibaAnalyzer v8.4.0 |
| 2026-07-08 | Solution implement in ibaDatCoordinator v4.1.1 |
