CVE-2026-31278
Received Received - Intake

Active Directory Credential Exposure in Suprema BioStar

Vulnerability report for CVE-2026-31278, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: MITRE

Description

An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
suprema biostar_2 to 2.9.12 (exc)
suprema biostar_x to 1.0.2 (exc)
suprema biostar_2 to 2.9.5.29 (inc)
suprema biostar_2 to 2.9.5.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-319 The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-31278 is a vulnerability in Suprema BioStar 2 and BioStar X systems where an attacker can retrieve Active Directory service account credentials in plaintext by sending a crafted GET request to the /api/v2/setting/adserversetting endpoint. The credentials are exposed despite being masked in the admin UI, allowing unauthorized LDAP authentication against Active Directory.

Detection Guidance

To detect this vulnerability, check if your BioStar 2 or BioStar X system is running a vulnerable version (BioStar 2 before 2.9.12 or BioStar X before 1.0.2). Use network monitoring tools to inspect GET requests to the /api/v2/setting/adserversetting endpoint for plaintext Active Directory credentials. Verify if the API response includes unencrypted passwords despite the UI masking them.

Impact Analysis

This vulnerability allows attackers to obtain Active Directory credentials, enabling LDAP authentication. This can lead to domain user enumeration, internal network reconnaissance, lateral movement within the network, and potential privilege escalation depending on the service account permissions.

Compliance Impact

This vulnerability exposes Active Directory service account credentials in cleartext, which could lead to unauthorized access to sensitive systems and data. For GDPR, this may violate principles of data protection by design and default, as well as requirements for confidentiality and integrity of personal data. Under HIPAA, it could compromise protected health information if the system is used in healthcare settings, potentially violating security rule requirements for access controls and transmission security.

Mitigation Strategies

Immediately update BioStar 2 to version 2.9.12 or later and BioStar X to version 1.0.2 or later. Rotate all Active Directory service account credentials. Restrict API access to trusted network segments and enable LDAPS (SSL) for Active Directory communication to prevent credential exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-31278. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart