# CVE-2025-59106

## Summary

- **CVE ID:** CVE-2025-59106
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-272
- **Published:** Jan 26, 2026
- **Last Modified:** Mar 13, 2026

## Description

The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges.

## Affected Products

- dormakaba — Access Manager 92xx-k7 (92xx-k7: <BAME 06.00)

## References

- [CNA](https://r.sec-consult.com/dormakaba)
- [CNA](https://r.sec-consult.com/dkaccess)
- [CNA](https://www.dormakabagroup.com/en/security-advisories)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.71%
- **EPSS Percentile:** 51.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._