HIGH
supremainc
CVE published 2026-09-14
CVE-2026-31278
CVE-2026-31278 is a high-severity vulnerability in Suprema BioStar 2 and BioStar X systems, allowing attackers to obtain Active Directory service account credentials in cleartext via a crafted GET request to the /api/v2/setting/adserversetting endpoint. Defenders should prioritize verifying and mitigating this vulnerability, especially in sensitive environments or systems exposed to the internet. The vuln [truncated]