| Publishing Date | 2026-06-17 |
|---|---|
| Last Update | 2026-06-17 |
| Tracking ID | IBA-2026-08 |
| CVE | CVE-2026-8024 |
| CVSS Base Score | 9.8 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Summary
A vulnerability has been identified in ibaPDA and ibaDatCoordinator. The affected applications do not properly restrict the .NET BinaryFormatter when deserializing client-server input. This could allow an attacker to cause a type confusion and execute arbitrary code within the affected applications. This is the same issue that exists for the .NET BinaryFormatter: https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300.
Affected products
This applies to all iba products up to the versions listed below:
- ibaPDA v8.13.4
- ibaDatCoordinator v4.0.6
How do I know that I’m affected?
If you have installed any of the products listed above, you are affected.
Mitigation
Restrict connections to localhost
- (Info: Applies only to ibaPDA. For ibaDatCoordinator, continue with the next step.) Go to I/O Manager → General and deactivate the option "Automatically open necessary ports in Windows Firewall." (If this option remains active, after a restart of ibaPDA or a restart for data acquisition, the firewall will be reconfigured automatically.)
- Then go to Advanced Windows Firewall settings and delete or deactivate all incoming rules for the ibaPDA / ibaDatCoordinator Client and Server.
- Create manual firewall rules for the connection you use for ibaPDA or ibaDatCoordinator and verify that you have the correct ports configured. Help regarding which ports the ibaPDA or ibaDatCoordinator Service uses can be found in the iba Help Center.
Important: After the change, verify that all ibaPDA or ibaDatCoordinator services are working as expected and that the data acquisition is functioning correctly.
Solution
With the following versions, the issue has been fixed:
- ibaPDA v8.14.0
- ibaDatCoordinator v4.0.7
Customer Actions
Please install the update as described in the solution
Acknowledgements
iba AG thanks the following parties for their efforts:
- Security Researchers from tenable for reporting (see: www.tenable.com)
- CERTVDE for coordination. (see: https://certvde.com/en/)
References
- iba AG Product Security Advisories (external) https://www.iba-ag.com/en/security
- CERT@VDE Security Advisories for iba AG (external) https://certvde.com/de/advisories/vendor/iba/
- VDE-2026-051: iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator - HTML (self) https://certvde.com/en/advisories/VDE-2026-051
- VDE-2026-051: iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator - CSAF (self) https://iba.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-051.json
Timeline
| 2026-04-16 | Information from Tenable to the Security Team |
| 2026-06-17 | Fix for the issue in ibaPDA v8.14.0 |
| 2026-06-17 | Fix for the issue in ibaDatCoordinator v4.0.7 |
