CVE-2025-59106: Web Server Running with Root Privileges in dormakaba access manager

Published Jan 26, 2026
·
Updated

The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges.

Affected Software

13 affected components
dormakaba Access Manager
All of the following
Dormakabagroup Dormakaba Access Manager 9200-k7 Firmware<bame_06.00
Dormakabagroup Dormakaba Access Manager 9200-k7
All of the following
Dormakabagroup Dormakaba Access Manager 9230-k7 Firmware<bame_06.00
Dormakabagroup Dormakaba Access Manager 9230-k7
All of the following
Dormakabagroup Dormakaba Access Manager 9290-k7 Firmware<bame_06.00
Dormakabagroup Dormakaba Access Manager 9290-k7
All of the following
Dormakabagroup Dormakaba Access Manager 9200-k5 Firmware
Dormakabagroup Dormakaba Access Manager 9200-k5
All of the following
Dormakabagroup Dormakaba Access Manager 9230-k5 Firmware
Dormakabagroup Dormakaba Access Manager 9230-k5
All of the following
Dormakabagroup Dormakaba Access Manager 9290-k5 Firmware
Dormakabagroup Dormakaba Access Manager 9290-k5

Remediation

Information

To secure the devices from unauthorized access, it is highly recommended to change the default password and update to at least firmware version BAME 06.00.x RA.

Event History

Jan 26, 2026
CVE Published
via MITRE·10:06 AM
Data Sourced
via MITRE·10:06 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-59106?

CVE-2025-59106 is classified as a high severity vulnerability due to the web server running with root privileges.

2

How do I fix CVE-2025-59106?

To fix CVE-2025-59106, reconfigure the web server to run with the least privilege principle and ensure it does not execute actions with root privileges.

3

What systems are affected by CVE-2025-59106?

CVE-2025-59106 affects the dormakaba Access Manager software.

4

What is the impact of CVE-2025-59106?

The impact of CVE-2025-59106 includes potential unauthorized code execution and increased risk of system compromise.

5

Is there a patch available for CVE-2025-59106?

As of now, there is no publicly disclosed patch for CVE-2025-59106, but it is advisable to monitor updates from dormakaba.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203