SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-59106

The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges.

HIGH 8.8EPSS 0.71%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.71% probability · 52th percentile
CISA KEV
Not listed
Weakness
CWE-272
Affected
dormakabagroup/dormakaba access manager 9200-k7 firmware · dormakabagroup/dormakaba access manager 9230-k7 firmware · dormakabagroup/dormakaba access manager 9290-k7 firmware · dormakabagroup/dormakaba access manager 9200-k5 firmware · dormakabagroup/dormakaba access manager 9230-k5 firmware · dormakabagroup/dormakaba access manager 9290-k5 firmware
Source
551230f0-3615-47bd-b7cc-93e92e730bbf

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.