CTIPilot

Abacus ERP

product · product:abacus-erp

Coverage timeline
1
first 2026-07-17 → last 2026-07-17
Peak priority
high
1 high
Sources cited
3
2 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
2
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

Releases covered
Abacus ERP
ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-17/abacus-erp-unauth-rce-path-traversal-ncsc-ch · ATT&CK page ↗

Story timeline

  1. 2026-07-17Abacus ERP: unauthenticated RCE (CVSS 9.8, no CVE) and authenticated path traversal in a widely-deployed Swiss ERP platform, flagged by NCSC-CH
    trending-vulnerabilitiesNCSC-CH flags an unauthenticated RCE (CVSS 9.8) in Abacus ERP; reachable endpoint is the only prerequisite

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • security.abacus.ch2 (67%)
  • security-hub.ncsc.admin.ch1 (33%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Abacus ERP (1)

2026-07-17 · view entry permalink →

HIGHNATOA2

Abacus ERP: unauthenticated RCE (CVSS 9.8, no CVE) and authenticated path traversal in a widely-deployed Swiss ERP platform, flagged by NCSC-CH

Abacus Research AG (Wittenbach, SG) patched two unrelated flaws on 2026-07-15 that NCSC-CH surfaced the following day (NCSC-CH, 2026-07-16). The critical one is an unauthenticated remote code execution in the server-side handler of the proprietary Abacus client-server communication protocol: "the vulnerability allows remote code execution on the abacus server without user authentication," and "reachable Abacus Endpoints are the only prerequisite for an attack", no credentials, no user interaction (Abacus Research AG, 2026-07-15). The vendor states the flaw is not limited by license or option: every on-prem Abacus ERP installation is affected, and End-of-Life V2023-and-earlier builds remain vulnerable with no fix planned. The second flaw (CVSS 7.7) is a path traversal in two APIs tied to the AbaClik / AbaClik.ai mobile companion apps that lets an authenticated caller read a subset of server files outside the application's security realm; NCSC-CH's load-bearing point is that these APIs are network-exposed by default even for customers who do not use the mobile apps (Abacus Research AG, 2026-07-15).

Both were found through Abacus's own bug-bounty program and the vendor reports no indication of exploitation in the wild. Internet-facing on-prem deployments are the acute case; an internal-only Abacus still carries the flaw but with the attack surface reduced to the internal network.

If successfully exploited, the vulnerability allows remote code execution on the abacus server without user authentication.

Reachable Abacus Endpoints are the only prerequisite for an attack.

No, the vulnerability was found in our bugbounty program. We have no indications of a successful attack in the wild.

Abacus Research AG
vulnerability17 Jul 04:35Zmulti-sourceOpen finding ↗