Junglewise Threat Intelligence

CVE-2025-60534: Blue Access Cobalt authentication bypass in web application

CVE-2025-60534 · Severity: critical · CVSS 9.8 · Published 2026-01-06

Executive brief

Blue Access Cobalt, a system used for managing physical door security and access control, contains a critical security flaw. An unauthorized person can bypass the login screen to gain full administrative control over the application. This could allow an attacker to remotely unlock doors, manage user permissions, or disrupt physical security operations without needing a valid username or password.

Technical details

An authentication bypass vulnerability (CWE-287) exists in Blue Access Cobalt v02.000.195 and earlier. The flaw allows a remote, unauthenticated attacker to selectively proxy requests to the web application's backend functionality. By bypassing the authentication mechanism, the attacker can gain full administrative access to the application and the connected door control systems. The attack is network-reachable, requires no user interaction, and has low complexity. As of the current advisory, a full technical writeup is pending, and users are advised to contact the vendor for patching information.

Affected products

  • Blue Access Tech Cobalt X1 02.000.195 and earlier

Timeline

  • 2026-01-06: advisory
  • 2026-01-06: disclosed

References