logo

CVE-2026-9509 | Suprema BioStar 2 2.9.8/2.9.10/2.9.11 /api/migration uncaught exception

ID: e0da7fa1-5c5b-557f-95aa-bf92602aa51b

STIX ID: report--e0da7fa1-5c5b-557f-95aa-bf92602aa51b

Feed Name: VulDB Recent Entries

Threat Score
50/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: vuldb.com

...
...

A remote, unauthenticated denial-of-service vulnerability (CVE-2026-9509) affecting Suprema BioStar 2 Server versions 2.9.8, 2.9.10, and 2.9.11 was reported; sending crafted HTTP POST requests to the /api/migration endpoint triggers an uncaught exception that halts critical services and leaves access control systems offline until manual restart. Technical details are published by the researcher (Jordi Garcia Ribera) and advisory (incibe.es); exploitation is described as trivial to automate but no public exploit or mitigations are documented.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.