OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97898

HIGH · CVSS 8.4 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The Akia keyless entry cloud service is vulnerable due to insecure direct object references, allowing authenticated guests to unlock rooms they are not authorized to access by manipulating room identifiers. This flaw poses a significant risk of unauthorized physical access to guest rooms, impacting the security of properties using this service. Hotels and property management systems utilizing the Akia service should prioritize remediation to safeguard guest privacy and security.

CVE
CVE-2026-97898
Severity
HIGH
CVSS
8.4
EPSS
0.24%

Original NVD Description

Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unlock action is relying on a client-supplied room/door identifier that is not properly authorized server-side against the authenticated guest's booking. An authenticated guest could unlock rooms other than their own, resulting in unauthorized physical access to guest rooms at an affected property. As of 19th September 2026 the service is no more vulnerable to this attack (feedback received by the reporter).  The attack is remote but the effect is local to an affected property.