HIGH
CVE-2026-31278
CVSS
7.7
Description
An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.
Weakness (CWE)
CWE-319
Cleartext Transmission
EPSS Score
0.17%
Probability of exploitation in next 30 days
6.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.