CVE-2025-59106: Web Server Running with Root Privileges in dormakaba access manager
The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59106?
CVE-2025-59106 is classified as a high severity vulnerability due to the web server running with root privileges.
How do I fix CVE-2025-59106?
To fix CVE-2025-59106, reconfigure the web server to run with the least privilege principle and ensure it does not execute actions with root privileges.
What systems are affected by CVE-2025-59106?
CVE-2025-59106 affects the dormakaba Access Manager software.
What is the impact of CVE-2025-59106?
The impact of CVE-2025-59106 includes potential unauthorized code execution and increased risk of system compromise.
Is there a patch available for CVE-2025-59106?
As of now, there is no publicly disclosed patch for CVE-2025-59106, but it is advisable to monitor updates from dormakaba.