CVE-2025-59093: Insecure Password Derivation Function for Database Administrator in dormakaba Kaba exos 9300

Published Jan 26, 2026
·
Updated

Exos 9300 instances are using a randomly generated database password to connect to the configured MSSQL server. The password is derived from static random values, which are concatenated to the hostname and a random string that can be read by every user from the registry. This allows an attacker to derive the database password and get authenticated access to the central exos 9300 database as the user Exos9300Common. The user has the roles ExosDialog and ExosDialogDotNet assigned, which are able to read most tables of the database as well as update and insert into many tables.

Affected Software

1 affected component
dormakaba Kaba exos 9300

Remediation

Information

As mitigation, direct access to the database and manipulation of the rich client or their communication must be ruled out. This can be achieved by operating the rich clients and their application services in a secure environment with a correspondingly limited connection to the user.

Event History

Jan 26, 2026
CVE Published
via MITRE·10:03 AM
Data Sourced
via MITRE·10:03 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2025-59093?

CVE-2025-59093 is classified as a high-severity vulnerability due to its potential to allow unauthorized access to the MSSQL server.

2

How do I fix CVE-2025-59093?

To mitigate CVE-2025-59093, ensure that a secure and unique password derivation function is implemented for database connections.

3

Who is affected by CVE-2025-59093?

CVE-2025-59093 affects instances of dormakaba Kaba exos 9300 that use a randomly generated database password for MSSQL server connections.

4

What are the implications of CVE-2025-59093?

The implications of CVE-2025-59093 include the risk of compromised database security, leading to potential data breaches.

5

When was CVE-2025-59093 disclosed?

CVE-2025-59093 was disclosed recently as part of ongoing security assessments of dormakaba systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203