CVE-2026-97898

8.4

Akia · Keyless Entry Cloud Service

A missing authorization flaw in the Akia keyless entry service allows authenticated guests to unlock doors for which they do not have authorization by manipulating room identifiers.

Executive summary

An insecure direct object reference vulnerability in the Akia keyless entry cloud service could allow an authenticated guest to gain unauthorized physical access to rooms at an affected property.

Vulnerability

The service suffers from a missing object-level authorization flaw where the unlock action relies on a client-supplied room identifier without server-side validation against the user's booking. This allows an authenticated guest to bypass intended access controls and unlock rooms other than their own.

Business impact

The ability to gain unauthorized physical access to guest rooms poses a severe risk to guest safety, property security, and brand reputation. With a CVSS score of 8.4, this high-severity vulnerability highlights a significant failure in access control, which could lead to theft, liability issues, and loss of customer trust.

Remediation

Immediate Action: Ensure the environment is updated to version 2026.10.19 or later, as the vendor has confirmed the fix was deployed to the cloud service as of September 19, 2026.

Proactive Monitoring: Review access logs for the keyless entry system to identify any anomalous unlock requests or patterns where a single user account attempts to access multiple room identifiers.

Compensating Controls: If legacy instances remain that are not automatically updated, restrict access to the keyless entry API endpoints through a Web Application Firewall, and implement strict rate limiting to detect and block sequential ID enumeration attempts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a critical security oversight involving physical access control. Organizations utilizing the Akia keyless entry system should verify that their cloud instance has received the necessary updates and perform a thorough audit of access logs to ensure no unauthorized entries occurred prior to the patch deployment. Immediate confirmation of the updated environment version is required to maintain the security of physical premises.

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Philipp Brügger, per the CVE Program record.