PatchSiren

supremainc CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH supremainc CVE published 2026-09-14

CVE-2026-31278

CVE-2026-31278 is a high-severity vulnerability in Suprema BioStar 2 and BioStar X systems, allowing attackers to obtain Active Directory service account credentials in cleartext via a crafted GET request to the /api/v2/setting/adserversetting endpoint. Defenders should prioritize verifying and mitigating this vulnerability, especially in sensitive environments or systems exposed to the internet. The vuln [truncated]