Back

CRITICAL

Incorrect Permission Assignment for Critical Resource vulnerability in Suprema's BioStar

Published May 29, 2026

Description

Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the administrator configures their path within the NGINX webroot. This vulnerability allows an attacker with network access to directly download backup ZIP files via ‘http(s)://[server]/download/…’ without requiring authentication. This exposes highly sensitive information that can lead to server impersonation, unauthorized access to databases, and lateral movement.

Affected products

Remediation

Vendor solution

The vulnerability has been fixed by the Suprema team. We recommend updating to the latest available version.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published May 29, 2026
Updated May 29, 2026
Reserved May 25, 2026
CISA Vulnrichment
Updated May 29, 2026
NVD
Status Deferred
Modified Jul 21, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner INCIBE
Published May 29, 2026
Updated May 29, 2026
Exploited since n/a
EUVD-2026-33282