CVE-2026-31278: High severity Suprema BioStar 2 vulnerability
Published Sep 14, 2026
·Updated
An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.
Affected Software
2 affected components
Suprema BioStar 2<2.9.12
Suprema BioStar X<1.0.2
Event History
Sep 14, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Suprema BioStar 2 versions before 2.9.12 and Suprema BioStar X versions before 1.0.2 are affected.
2
What access does an attacker need to exploit this issue?
The vector is network-accessible and requires low privileges. No user interaction is required; an attacker supplies a crafted GET request to the affected API endpoint.
3
What data can be exposed?
The affected endpoint can disclose Active Directory service account credentials in cleartext. The provided data does not indicate any direct integrity or availability impact.