CVE-2026-97898High· 8.4▾ TwilightInsecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unlock action is relying on a client-supplied room/door identifier that is not properly authorized server-side against the…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unlock action is relying on a client-supplied room/door identifier that is not properly authorized server-side against the authenticated guest's booking. An authenticated guest could unlock rooms other than their own, resulting in unauthorized physical access to guest rooms at an affected property.
As of 19th September 2026 the service is no more vulnerable to this attack (feedback received by the reporter).
The attack is remote but the effect is local to an affected property.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53626High· 7.1GLPI is a free asset and IT management software package
CVE-2026-52850Medium· 4.3Docmost is open-source collaborative wiki and documentation software
CVE-2026-54671High· 8.8WeGIA is a web manager for charitable institutions
CVE-2026-53546Critical· 9.6Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities
CVE-2026-18121Medium· 6.3Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calend…
CVE-2026-16105Medium· 4.9A flaw was found in the RoleContainerResource component of Keycloak