CVE-2026-31278: CWE-319 Cleartext Transmission of Sensitive Information in supremainc BioStar 2
CVE-2026-31278 is a vulnerability in Suprema BioStar 2 and BioStar X that allows attackers to retrieve Active Directory service account credentials in cleartext via a crafted GET request to the /api/v2/setting/adserversetting endpoint. This affects BioStar 2 versions before 2.9.12 and BioStar X versions before 1.0.2. The vulnerability has a high severity with a CVSS score of 7.7. No patch information is provided in the data.
AI Analysis
Technical Summary
The vulnerability CVE-2026-31278 involves cleartext transmission of sensitive information (Active Directory service account credentials) through the /api/v2/setting/adserversetting endpoint in Suprema BioStar 2 prior to version 2.9.12 and BioStar X prior to 1.0.2. An attacker with low privileges can send a crafted GET request to obtain these credentials in cleartext, potentially compromising Active Directory authentication. The CVSS v3.1 score is 7.7, indicating high severity, with network attack vector, low attack complexity, and no user interaction required. The impact is confidentiality loss without integrity or availability impact.
Potential Impact
An attacker with low privileges can obtain Active Directory service account credentials in cleartext, leading to a high confidentiality impact. This could facilitate further unauthorized access or lateral movement within the affected environment. There is no reported impact on integrity or availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the vulnerable endpoint and monitor for suspicious GET requests targeting /api/v2/setting/adserversetting. Avoid exposing the service to untrusted networks.
CVE-2026-31278: CWE-319 Cleartext Transmission of Sensitive Information in supremainc BioStar 2
Description
CVE-2026-31278 is a vulnerability in Suprema BioStar 2 and BioStar X that allows attackers to retrieve Active Directory service account credentials in cleartext via a crafted GET request to the /api/v2/setting/adserversetting endpoint. This affects BioStar 2 versions before 2.9.12 and BioStar X versions before 1.0.2. The vulnerability has a high severity with a CVSS score of 7.7. No patch information is provided in the data.
CVSS v3.1
Score 7.7high
Affected software
supremainc
BioStar 2
pkg:github/supremainc/biostar2Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-31278 involves cleartext transmission of sensitive information (Active Directory service account credentials) through the /api/v2/setting/adserversetting endpoint in Suprema BioStar 2 prior to version 2.9.12 and BioStar X prior to 1.0.2. An attacker with low privileges can send a crafted GET request to obtain these credentials in cleartext, potentially compromising Active Directory authentication. The CVSS v3.1 score is 7.7, indicating high severity, with network attack vector, low attack complexity, and no user interaction required. The impact is confidentiality loss without integrity or availability impact.
Potential Impact
An attacker with low privileges can obtain Active Directory service account credentials in cleartext, leading to a high confidentiality impact. This could facilitate further unauthorized access or lateral movement within the affected environment. There is no reported impact on integrity or availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the vulnerable endpoint and monitor for suspicious GET requests targeting /api/v2/setting/adserversetting. Avoid exposing the service to untrusted networks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-03-09T00:00:00.000Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa7521c55bf5e2cf55cf3a0
Added to database: 09/14/2026, 01:47:08 UTC
Last enriched: 09/14/2026, 02:01:28 UTC
Last updated: 09/14/2026, 03:01:20 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.