Executive brief
Suprema BioStar 2, a security platform used for access control and biometric management, contains a vulnerability that allows unauthorized individuals to download full system backups. If an administrator has configured backup paths within the web server's directory, an attacker can access these files over the internet without a password. This could lead to the theft of sensitive databases, server impersonation, and a total compromise of the security system.
Technical details
A vulnerability classified as CWE-732 (Incorrect Permission Assignment for Critical Resource) exists in Suprema BioStar 2 versions 2.9.3 through 2.9.11. When an administrator configures the backup path within the NGINX webroot, the application fails to enforce proper access controls on the resulting directory. An unauthenticated attacker can perform a direct request to the '/download/...' path to retrieve ZIP archives containing sensitive system data. This data can be leveraged for database access, lateral movement, or server impersonation. The vendor has released patches to address this issue, and users are advised to update to the latest version.
Affected products
- Suprema BioStar 2 (Server) 2.9.3 through 2.9.11
Timeline
- 2026-05-29: disclosed: Coordinated disclosure by INCIBE and Jordi Garcia Ribera
- 2026-05-29: advisory
- 2026-05-29: patched: Fixed in latest available versions according to INCIBE advisory