CVE-2025-59106
8.8dormakaba · Access Manager
The dormakaba Access Manager web server binary runs with root privileges, allowing attackers who achieve code execution to gain full control over the physical access control system.
Executive summary
A critical privilege escalation vulnerability in dormakaba Access Manager allows authenticated attackers to execute commands with root-level privileges, potentially compromising physical security infrastructure.
Vulnerability
The vulnerability involves a violation of the principle of least privilege, where the web server binary executes all web UI actions with root permissions. An authenticated attacker who successfully exploits a separate vulnerability to execute code can escalate their privileges to the highest level on the device.
Business impact
Successful exploitation of this vulnerability poses a severe risk to organizations, as it grants an attacker complete control over physical access control systems. This could allow unauthorized entry into restricted areas, reconfiguration of security controllers, or the disabling of alarm systems. Given the CVSS score of 8.8, this flaw represents a high risk to the integrity and availability of critical facility security infrastructure.
Remediation
Immediate Action: Update the affected device firmware to at least version BAME 06.00.x RA and ensure that default administrative passwords are changed immediately to prevent unauthorized access.
Proactive Monitoring: Monitor system access logs for anomalous activity, such as unexpected administrative logins or unauthorized attempts to reconfigure access control parameters.
Compensating Controls: Restrict network access to the management interface of the Access Manager to trusted internal segments only, and utilize network segmentation to isolate physical security hardware from general business traffic.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations utilizing dormakaba Access Manager systems must prioritize the firmware update to version BAME 06.00.x RA to remediate this privilege escalation flaw. Because this device controls critical physical access, failing to apply this update leaves the facility vulnerable to unauthorized entry and total system subversion. Security teams should treat this as a high-priority maintenance item and verify that all administrative credentials have been hardened beyond factory defaults.
More dormakaba CVEs
Sources
Originally found and disclosed by Clemens Stockenreitner, SEC Consult Vulnerability Lab, Werner Schober, SEC Consult Vulnerability Lab, per the CVE Program record.