Security Advisory

CVE-2026-9509

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-29 12:11:07
Last updated 2026-05-29 13:33:02
Assigner INCIBE
CVSS score not scored
State PUBLISHED

Description

An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated remote attacker to cause a denial of service (DoS) by sending HTTP POST requests to the ‘/api/migration’ endpoint. This request triggers a failure that halts critical processes, leaving the system offline until the services or server are manually restarted. As a result, access control readers cease to function, and potential failures may occur in third-party integrations. Since the exploit requires no privileges or user interaction and is trivial to automate, the impact on availability is high, and the effect extends to interconnected systems.