ZeroHour

CVE-2026-31278

moderate

Cleartext Active Directory Credential Disclosure in Suprema BioStar 2 and BioStar X

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

Suprema BioStar 2 before 2.9.12 and BioStar X before 1.0.2 expose Active Directory service account credentials in cleartext through the /api/v2/setting/adserversetting API endpoint. An attacker with any authenticated (low-privilege) account on the BioStar web server can send a crafted GET request to that endpoint and retrieve the stored AD credentials in plaintext. Because these are directory service credentials, successful abuse can enable lateral movement and privilege escalation across the customer's Windows domain, not just within the access-control system. Organizations running unpatched BioStar 2 or BioStar X deployments, especially ones with many low-privilege operator or user accounts, are affected. No public proof of concept is known and the flaw is not listed in the CISA KEV catalog, so exploitation status is currently none known.

What to do: Upgrade BioStar 2 to version 2.9.12 or later and BioStar X to version 1.0.2 or later. Rotate the Active Directory service account credentials used for AD integration if an affected version was deployed, and review domain authentication logs for suspicious use of that account. Restrict access to the BioStar web API to trusted administrators and networks, and ensure BioStar servers are not exposed to the public internet.

Affected
Suprema BioStar 2before 2.9.12
Suprema BioStar Xbefore 1.0.2
Estimated exposure
moderate≈ several thousand internet-exposed BioStar servers out of a larger on-premises installed base (estimate) — BioStar 2 is enterprise access-control software deployed on-premises worldwide, and historical internet-wide scans have repeatedly found a few thousand exposed BioStar 2 web servers, so exposure is estimated in the low thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.

Weakness
CWE-319
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.