The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is hard-coded in multiple locations as well as documented in the locally stored user documentation.
Advisories

No advisories yet.

Fixes

Solution

Make sure to change the default password for the extended admin mode in the admin tool to a new password.


Workaround

No workaround given by the vendor.

History

Mon, 26 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 10:15:00 +0000

Type Values Removed Values Added
Description The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is hard-coded in multiple locations as well as documented in the locally stored user documentation.
Title Weak Default Password in dormakaba Kaba exos 9300
Weaknesses CWE-798
References
Metrics cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: SEC-VLab

Published:

Updated: 2026-01-26T16:10:20.331Z

Reserved: 2025-09-09T07:52:56.383Z

Link: CVE-2025-59096

cve-icon Vulnrichment

Updated: 2026-01-26T16:10:17.160Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-26T10:16:07.113

Modified: 2026-01-26T15:03:33.357

Link: CVE-2025-59096

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses