CVE-2026-9509: Uncaught exception vulnerability in Suprema's BioStar
An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated remote attacker to cause a denial of service (DoS) by sending HTTP POST requests to the ‘/api/migration’ endpoint. This request triggers a failure that halts critical processes, leaving the system offline until the services or server are manually restarted. As a result, access control readers cease to function, and potential failures may occur in third-party integrations. Since the exploit requires no privileges or user interaction and is trivial to automate, the impact on availability is high, and the effect extends to interconnected systems.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9509?
CVE-2026-9509 has a high severity rating of 8.7 according to the CVSS v4.0.
How do I fix CVE-2026-9509?
To fix CVE-2026-9509, update the Suprema BioStar 2 Server to the latest available version.
What type of attack does CVE-2026-9509 allow?
CVE-2026-9509 allows an unauthenticated remote attacker to execute a denial of service (DoS) attack.
Which versions of Suprema BioStar are affected by CVE-2026-9509?
The affected versions of Suprema BioStar are 2.9.8, 2.9.10, and 2.9.11.
What causes the vulnerability in CVE-2026-9509?
The vulnerability in CVE-2026-9509 is caused by an unhandled exception triggered by HTTP POST requests to the '/api/migration' endpoint.