Skip to main navigation Skip to main content Skip to page footer

CVE‑2026‑26171 – Denial‑of‑Service Vulnerability in Third‑Party .NET Library

Security Advisories IBA-2026-07

Grüner Hintergrund mit kreisförmigem digitalem Interface-Design.
Publishing Date 20.04.2026
Last Update 08.07.2026
Tracking IDIBA-2026-07

Summary

A vulnerability (CVE‑2026‑26171) was reported in a third‑party .NET library used by the ibaHD server that could allow an unauthenticated remote attacker to cause a denial of service through uncontrolled resource consumption when processing specially crafted XML data; no active exploitation of this vulnerability in the product is currently known.

Affected products

This applies to all iba products up to the versions listed below:

  • ibaHD-Server v3.6.0
  • ibaCMC v3.7.1
  • ibaAnalyzer v8.3.5
  • ibaDatCoordinator v4.1.0

How do I know that I’m affected?

If you have installed any of the products listed above, you are affected.

Solution

With the following versions, the issue has been fixed:

  • ibaHD-Server v3.6.1
  • ibaCMC v3.7.2
  • ibaAnalyzer v8.4.0
  • ibaDatCoordinator v4.1.1

Customer Actions

Please install the update as described in the solution.

Timeline

2026-04-16Noted by the Security Team
2026-04-20Solution for the Problem in Version ibaHD-Server v3.6.1
2026-05-06Solution implement in ibaCMC v3.7.2
2026-06-06Solution implement in ibaAnalyzer v8.4.0
2026-07-08Solution implement in ibaDatCoordinator v4.1.1
Zurück zur Übersicht

Was möchten Sie heute machen?

Mit der Auswahl des Landes wird meine Anfrage an die zuständige Landesniederlassung der iba AG für Vertrieb und Support weitergeleitet.Datenschutz­erklärung