CVE-2026-27776

7.2

NTT DATA INTRAMART Corporation · intra-mart Accel Platform

The IM-LogicDesigner module in intra-mart Accel Platform is vulnerable to insecure deserialization, which may allow arbitrary code execution when importing a crafted file.

Executive summary

A critical insecure deserialization vulnerability in the intra-mart Accel Platform IM-LogicDesigner module allows an authenticated administrator to execute arbitrary code.

Vulnerability

This vulnerability involves the insecure deserialization of untrusted data (CWE-502) within the IM-LogicDesigner module. An attacker with administrative privileges can trigger code execution by importing a specifically crafted file into the system.

Business impact

Successful exploitation of this flaw allows an attacker to achieve arbitrary code execution on the underlying server. Given the high CVSS score of 7.2, this vulnerability represents a significant risk to the integrity and availability of the platform, potentially leading to a full system compromise.

Remediation

Immediate Action: Update the intra-mart Accel Platform to the latest version provided by the vendor, which addresses the deserialization flaw.

Proactive Monitoring: Review administrative access logs and file import activity within the IM-LogicDesigner module for signs of unauthorized or suspicious file processing.

Compensating Controls: Restrict administrative access to the IM-LogicDesigner module to a limited group of trusted users to reduce the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing the intra-mart Accel Platform must prioritize upgrading their software to the latest version to mitigate this critical deserialization risk. Given the potential for complete system compromise via arbitrary code execution, this update should be scheduled as a high-priority maintenance task.

Sources