CVE 8.8 HIGH

Web Server Running with Root Privileges in dormakaba access manager_CVE-2025-59106

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges.

Basic Information

ID CVE-2025-59106
Source SEC-VLab
Published Jan 26, 2026 at 10:06
Modified Jan 27, 2026 at 18:44

Affected Product

Vendor dormakaba
Product Access Manager 92xx-k7
Version 92xx-k7: <BAME 06.00
Affected Versions dormakaba Access Manager 92xx-k7 92xx-k7: <BAME 06.00

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.