# CVE-2026-31278

## Summary

- **CVE ID:** CVE-2026-31278
- **Severity:** HIGH
- **CVSS Score:** 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
- **CWE:** CWE-319
- **Published:** Sep 14, 2026
- **Last Modified:** Sep 16, 2026

## Description

An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.

## Affected Products

- supremainc — BioStar 2 (0)

## References

- [CNA](https://www.supremainc.com)
- [CNA](https://github.com/mda1r/biostar2-ad-credential-exposure)
- [CISA-ADP](https://github.com/mda1r/CVE-2026-31278)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 4.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._