{"id":"CVE-2026-31278","title":"An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET re…","summary":"An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET re…","severity":"high","cvss":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-319"],"vendor":"supremainc","product":"BioStar 2","affected":["biostar_2 < 2.9.12"],"published":"2026-09-14","updated":"2026-09-22","sourceUpdated":"2026-09-22T20:00:03.713","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-31278","references":[{"url":"https://github.com/mda1r/biostar2-ad-credential-exposure","label":"cve@mitre.org"},{"url":"https://www.supremainc.com","label":"cve@mitre.org"},{"url":"https://github.com/mda1r/CVE-2026-31278","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","exploit-available","cve.org"],"epss":0.00167,"epssPercentile":0.06363,"exploits":{"github":1,"githubRepos":["https://github.com/mda1r/CVE-2026-31278"],"checkedAt":"2026-09-24T07:53:01.910Z"},"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-16T14:26:12.919730Z"},"ingestedAt":"2026-09-14T15:23:07.467Z","slug":"CVE-2026-31278","body":"## Overview\n\nAn issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":42.4,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[]}