iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator
[VDE-2026-051] A vulnerability has been identified in ibaPDA, ibaDatCoordinator and ibaLogic. The affected applications do not properly restrict the .NET BinaryFormatter when deserializing client-server input. This could allow an attacker to cause a type confusion and execute arbitrary code within the affected applications. This is the same issue that exists for the .NET BinaryFormatter: https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300.
EPSS 0.01 CVE-2026-8024 iba DE