← All Advisories

Suprema BioStar 2 Exposes Backup ZIP Files Without Authentication When Administrator Places the Backup Path Inside the NGINX Webroot, Allowing Database Download and Server Impersonation

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-9508

Key Details

CVECVE-2026-9508
CVSS Score / Version10.0 (Critical) / CVSS v4.0
Updated2026-07-21
Classified asCWE-732 (Incorrect Permission Assignment for Critical Resource)

What to Know

Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the administrator configures their path within the NGINX webroot. This vulnerability allows an attacker with network access to directly download backup ZIP files via ‘http(s)://[server]/download/…’ without requiring authentication. This exposes highly sensitive information that can lead to server impersonation, unauthorized access to databases, and lateral movement. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-9508
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-9508