What happened
An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.
Affected versions
BioStar 2: before 2.9.12 (semver) Fixed: See vendor advisory.
Why it matters
Review the vendor advisory and exposure of the affected product to determine operational impact.
Detection & mitigation
- Apply vendor-provided updates or mitigations.
- Review affected product exposure and access logs.
Public PoC references
RepositoryAuthorFirst seenReference
mda1r/CVE-2026-31278CVE write-up for Active Directory credential exposure vulnerability in Suprema BioStar 2★ 0mda1r2026-03-25VerifiedSource timeline
CVE record published by NVDView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.