The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
To secure the devices from unauthorized access, it is highly recommended to change the default password and update to at least firmware version BAME 06.00.x RA.
Workaround
No workaround given by the vendor.
References
History
Mon, 26 Jan 2026 19:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges. | |
| Title | Web Server Running with Root Privileges in dormakaba access manager | |
| Weaknesses | CWE-272 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: SEC-VLab
Published:
Updated: 2026-01-26T10:06:13.702Z
Reserved: 2025-09-09T07:53:12.879Z
Link: CVE-2025-59106
No data.
Status : Awaiting Analysis
Published: 2026-01-26T10:16:08.513
Modified: 2026-01-26T15:03:33.357
Link: CVE-2025-59106
No data.
OpenCVE Enrichment
No data.
Weaknesses