2026-07-17 · view entry permalink →
Abacus ERP: unauthenticated RCE (CVSS 9.8, no CVE) and authenticated path traversal in a widely-deployed Swiss ERP platform, flagged by NCSC-CH
Abacus Research AG (Wittenbach, SG) patched two unrelated flaws on 2026-07-15 that NCSC-CH surfaced the following day (NCSC-CH, 2026-07-16). The critical one is an unauthenticated remote code execution in the server-side handler of the proprietary Abacus client-server communication protocol: "the vulnerability allows remote code execution on the abacus server without user authentication," and "reachable Abacus Endpoints are the only prerequisite for an attack", no credentials, no user interaction (Abacus Research AG, 2026-07-15). The vendor states the flaw is not limited by license or option: every on-prem Abacus ERP installation is affected, and End-of-Life V2023-and-earlier builds remain vulnerable with no fix planned. The second flaw (CVSS 7.7) is a path traversal in two APIs tied to the AbaClik / AbaClik.ai mobile companion apps that lets an authenticated caller read a subset of server files outside the application's security realm; NCSC-CH's load-bearing point is that these APIs are network-exposed by default even for customers who do not use the mobile apps (Abacus Research AG, 2026-07-15).
Both were found through Abacus's own bug-bounty program and the vendor reports no indication of exploitation in the wild. Internet-facing on-prem deployments are the acute case; an internal-only Abacus still carries the flaw but with the attack surface reduced to the internal network.
If successfully exploited, the vulnerability allows remote code execution on the abacus server without user authentication.
Reachable Abacus Endpoints are the only prerequisite for an attack.
No, the vulnerability was found in our bugbounty program. We have no indications of a successful attack in the wild.