Executive brief
Suprema BioStar 2 and BioStar X are access control and biometric authentication platforms used to manage building and facility security. A vulnerability in the Active Directory configuration API endpoint returns service account passwords in cleartext to authenticated users, despite the UI masking them. An attacker with API access could obtain these credentials and use them to compromise the Active Directory infrastructure, enabling unauthorized access to domain systems and sensitive data.
Technical details
The /api/v2/setting/adserversetting endpoint in BioStar 2 before 2.9.12 and BioStar X before 1.0.2 improperly discloses Active Directory bind account credentials in plaintext API responses. Although the administrative UI masks the password field, an authenticated GET request to the endpoint returns the full unencrypted password along with LDAP configuration details and SSL settings. An authenticated attacker can retrieve these credentials with a simple GET request, potentially using them to perform LDAP enumeration, lateral movement, and privilege escalation within the Active Directory domain. Patches are available in BioStar 2 v2.9.12 and BioStar X v1.0.2.
Affected products
- Suprema BioStar 2 before 2.9.12
- Suprema BioStar X before 1.0.2
Timeline
- 2026-09-14: disclosed: CVE-2026-31278 published
- 2026-09-14: patched: BioStar 2 v2.9.12 and BioStar X v1.0.2 released