Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cleartext Exposure of Active Directory Service Credentials in Suprema BioStar 2 |
Mon, 14 Sep 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request. | |
| First Time appeared |
Supremainc
Supremainc biostar 2 |
|
| Weaknesses | CWE-319 | |
| CPEs | cpe:2.3:a:supremainc:biostar_2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Supremainc
Supremainc biostar 2 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-14T01:30:40.597Z
Reserved: 2026-03-09T00:00:00.000Z
Link: CVE-2026-31278
No data.
Status : Received
Published: 2026-09-14T02:17:14.080
Modified: 2026-09-14T02:17:14.080
Link: CVE-2026-31278
No data.
OpenCVE Enrichment
Updated: 2026-09-14T12:15:19Z