CVE-2026-9509: Uncaught exception vulnerability in Suprema's BioStar

Published May 29, 2026
·
Updated

An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated remote attacker to cause a denial of service (DoS) by sending HTTP POST requests to the ‘/api/migration’ endpoint. This request triggers a failure that halts critical processes, leaving the system offline until the services or server are manually restarted. As a result, access control readers cease to function, and potential failures may occur in third-party integrations. Since the exploit requires no privileges or user interaction and is trivial to automate, the impact on availability is high, and the effect extends to interconnected systems.

Affected Software

1 affected component
Suprema BioStar 2 Server=2.9.8, =2.9.10, =2.9.11

Event History

May 29, 2026
CVE Published
via MITRE·12:11 PM
Data Sourced
via MITRE·12:11 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Jun 29, 58424
Event
via FIRST·08:17 AM

Frequently Asked Questions

1

What is the severity of CVE-2026-9509?

CVE-2026-9509 has a high severity rating of 8.7 according to the CVSS v4.0.

2

How do I fix CVE-2026-9509?

To fix CVE-2026-9509, update the Suprema BioStar 2 Server to the latest available version.

3

What type of attack does CVE-2026-9509 allow?

CVE-2026-9509 allows an unauthenticated remote attacker to execute a denial of service (DoS) attack.

4

Which versions of Suprema BioStar are affected by CVE-2026-9509?

The affected versions of Suprema BioStar are 2.9.8, 2.9.10, and 2.9.11.

5

What causes the vulnerability in CVE-2026-9509?

The vulnerability in CVE-2026-9509 is caused by an unhandled exception triggered by HTTP POST requests to the '/api/migration' endpoint.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203