Junglewise Threat Intelligence

CVE-2026-9509: Suprema BioStar 2 denial of service via unhandled exception

CVE-2026-9509 · Severity: info · CVSS 8.7 · Published 2026-05-29

Technologies: Suprema BioStar 2. Vendors: Suprema.

Executive brief

A vulnerability in Suprema BioStar 2, a security platform used for access control and biometric identification, allows an attacker to crash the server remotely. By sending a specific request to the system, an attacker can disable the server and stop all connected door readers from functioning. This results in a total service outage that requires a manual restart to restore building security operations.

Technical details

The vulnerability is classified as an Uncaught Exception (CWE-248) within the '/api/migration' endpoint of the Suprema BioStar 2 Server. An unauthenticated remote attacker can trigger this exception by sending a specially crafted HTTP POST request. Because the application fails to handle the resulting error, critical server processes halt, leading to a complete Denial of Service (DoS). Exploitation requires no user interaction or privileges and results in the failure of access control readers and third-party integrations until a manual service restart is performed. The vendor has released patches to address this issue.

Affected products

  • Suprema BioStar 2 (Server) 2.9.8, 2.9.10, 2.9.11

Timeline

  • 2026-05-29: disclosed
  • 2026-05-29: advisory
  • 2026-05-29: patched

References

Related threats