CVE-2025-59106 Details
Description
The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges.
A vulnerability exists in the dormakaba Access Manager's web server, which is running with root privileges. This setup violates the principle of least privilege, as it allows an attacker to execute commands with the highest privileges if they can exploit other vulnerabilities to run code on the system. The issue is present in all versions of the Access Manager 9200-k5 and in the 9200-k7 Access Manager versions prior to BAME 06.00.
Users are advised to update to the latest version of the dormakaba Access Manager 9200-k7, which includes a patch for this vulnerability. For Access Manager 9200-k5, which does not support the necessary updates, it is recommended to replace the hardware with a newer model.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://r.sec-consult.com/dkaccess | SEC Consult Vulnerability Lab | Third Party Advisory |
| https://r.sec-consult.com/dormakaba | SEC Consult Vulnerability Lab | Third Party Advisory |
| https://www.dormakabagroup.com/en/security-advisories | SEC Consult Vulnerability Lab | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-272 | Least Privilege Violation | SEC Consult Vulnerability Lab |
Affected Products
| Product | Versions |
|---|---|
| dormakabagroup dormakaba access manager 9200-k7 firmware | < bame_06.00 |
CPE
Remediation
| |
| dormakabagroup dormakaba access manager 9200-k7 | All versions |
CPE
Remediation
| |
| dormakabagroup dormakaba access manager 9230-k7 firmware | < bame_06.00 |
CPE
Remediation
| |
| dormakabagroup dormakaba access manager 9230-k7 | All versions |
CPE
Remediation
| |
| dormakabagroup dormakaba access manager 9290-k7 firmware | < bame_06.00 |
CPE
Remediation
| |
| dormakabagroup dormakaba access manager 9290-k7 | All versions |
CPE
Remediation
| |
| dormakabagroup dormakaba access manager 9200-k5 firmware | All versions |
CPE
Remediation
| |
| dormakabagroup dormakaba access manager 9200-k5 | All versions |
CPE
Remediation
| |
| dormakabagroup dormakaba access manager 9230-k5 firmware | All versions |
CPE
Remediation
| |
| dormakabagroup dormakaba access manager 9230-k5 | All versions |
CPE
Remediation
| |
| dormakabagroup dormakaba access manager 9290-k5 firmware | All versions |
CPE
Remediation
| |
| dormakabagroup dormakaba access manager 9290-k5 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | SEC Consult Vulnerability Lab |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 12, 2026 | Initial Analysis | [email protected] |
| Jan 27, 2026 | CVE Modified | CISA-ADP |
| Jan 26, 2026 | New CVE Received | SEC Consult Vulnerability Lab |