8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges.
Basic Information
ID
CVE-2025-59106
Source
SEC-VLab
Published
Jan 26, 2026 at 10:06
Modified
Jan 27, 2026 at 18:44
Affected Product
Vendor
dormakaba
Product
Access Manager 92xx-k7
Version
92xx-k7: <BAME 06.00
Affected Versions
dormakaba Access Manager 92xx-k7 92xx-k7: <BAME 06.00