Skip to main navigation Skip to main content Skip to page footer

CVE‑2026‑26171 – Denial‑of‑Service Vulnerability in Third‑Party .NET Library

Security Advisories IBA-2026-07

Green background with a circular digital interface design.
Publishing Date 2026-04-20
Last Update 2026-07-08
Tracking IDIBA-2026-07

Summary

A vulnerability (CVE‑2026‑26171) was reported in a third‑party .NET library used by the ibaHD server that could allow an unauthenticated remote attacker to cause a denial of service through uncontrolled resource consumption when processing specially crafted XML data; no active exploitation of this vulnerability in the product is currently known.

Affected products

This applies to all iba products up to the versions listed below:

  • ibaHD-Server v3.6.0
  • ibaCMC v3.7.1
  • ibaAnalyzer v8.3.5
  • ibaDatCoordinator v4.1.0

How do I know that I’m affected?

If you have installed any of the products listed above, you are affected.

Solution

With the following versions, the issue has been fixed:

  • ibaHD-Server v3.6.1
  • ibaCMC v3.7.2
  • ibaAnalyzer v8.4.0
  • ibaDatCoordinator v4.1.1

Customer Actions

Please install the update as described in the solution.

Timeline

2026-04-16Noted by the Security Team
2026-04-20Solution for the Problem in Version ibaHD-Server v3.6.1
2026-05-06Solution implement in ibaCMC v3.7.2
2026-06-06Solution implement in ibaAnalyzer v8.4.0
2026-07-08Solution implement in ibaDatCoordinator v4.1.1
Back to List View

What would you like to do today?

By choosing a country, my request will be forwarded to the country branch of iba AG responsible for sales and support.Privacy Policy