CyberRota Analysis
AI-GeneratedThe Akia keyless entry cloud service is vulnerable due to insecure direct object references, allowing authenticated guests to unlock rooms they are not authorized to access by manipulating room identifiers. This flaw poses a significant risk of unauthorized physical access to guest rooms, impacting the security of properties using this service. Hotels and property management systems utilizing the Akia service should prioritize remediation to safeguard guest privacy and security.
Original NVD Description
Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unlock action is relying on a client-supplied room/door identifier that is not properly authorized server-side against the authenticated guest's booking. An authenticated guest could unlock rooms other than their own, resulting in unauthorized physical access to guest rooms at an affected property. As of 19th September 2026 the service is no more vulnerable to this attack (feedback received by the reporter). The attack is remote but the effect is local to an affected property.