CVE 8.8 HIGH

Unauthenticated Path Traversal in dormakaba access manager_CVE-2025-59099

8.8 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N

Description

The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a path traversal vulnerability, which allows an attacker to directly access files via simple GET requests without prior authentication.

Hence, it is possible to retrieve all files stored on the file system, including the SQLite database Database.sq3, containing badge information and the corresponding PIN codes. Additionally, when trying to access certain files, the web server crashes and becomes unreachable for about 60 seconds. This can be abused to continuously send the request and cause denial of service.

Basic Information

ID CVE-2025-59099
Source SEC-VLab
Published Jan 26, 2026 at 10:05

Affected Product

Vendor dormakaba
Product Access Manager 92xx-k5
Version 92xx-K5: <XAMB 04.05.21
Affected Versions dormakaba Access Manager 92xx-k5 92xx-K5: <XAMB 04.05.21
dormakaba Access Manager 92xx-k7 92xx-K7: <BAME 04.05.16

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.