Database Exposure Flaw in Dormakaba Products
CVE-2025-59100

5.9MEDIUM

Key Information:

Vendor

Dormakaba

Vendor
CVE Published:
26 January 2026

What is CVE-2025-59100?

The vulnerable web interface in Dormakaba access control systems allows for the export of an internal SQLite database. After attempting to export, the associated device is meant to reboot, which should delete the exported database. However, inconsistencies in the reboot process occasionally leave the exported database accessible. This flaw permits unauthorized access to sensitive information, including passwords, card PINs, and encrypted site keys, posing significant risks to user security and data integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Access Manager 92xx-k5 92xx-K5: <XAMB 04.06.212

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Clemens Stockenreitner, SEC Consult Vulnerability Lab
Werner Schober, SEC Consult Vulnerability Lab
.