CVE-2026-31278
moderateCleartext Active Directory Credential Disclosure in Suprema BioStar 2 and BioStar X
Suprema BioStar 2 before 2.9.12 and BioStar X before 1.0.2 expose Active Directory service account credentials in cleartext through the /api/v2/setting/adserversetting API endpoint. An attacker with any authenticated (low-privilege) account on the BioStar web server can send a crafted GET request to that endpoint and retrieve the stored AD credentials in plaintext. Because these are directory service credentials, successful abuse can enable lateral movement and privilege escalation across the customer's Windows domain, not just within the access-control system. Organizations running unpatched BioStar 2 or BioStar X deployments, especially ones with many low-privilege operator or user accounts, are affected. No public proof of concept is known and the flaw is not listed in the CISA KEV catalog, so exploitation status is currently none known.
What to do: Upgrade BioStar 2 to version 2.9.12 or later and BioStar X to version 1.0.2 or later. Rotate the Active Directory service account credentials used for AD integration if an affected version was deployed, and review domain authentication logs for suspicious use of that account. Restrict access to the BioStar web API to trusted administrators and networks, and ensure BioStar servers are not exposed to the public internet.
| Suprema BioStar 2 | before 2.9.12 |
| Suprema BioStar X | before 1.0.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.
- Weakness
- CWE-319
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.