CVE-2026-97898
Last modified
CVE-2026-97898 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unlock action is relying on a client-supplied room/door identifier that is not properly authorized server-side against the authenticated guest's booking.
Description
Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unlock action is relying on a client-supplied room/door identifier that is not properly authorized server-side against the authenticated guest's booking. An authenticated guest could unlock rooms other than their own, resulting in unauthorized physical access to guest rooms at an affected property. As of 19th September 2026 the service is no more vulnerable to this attack (feedback received by the reporter). The attack is remote but the effect is local to an affected property.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| akia | akia | < 2026.10.19 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-97898?
How severe is CVE-2026-97898?
How do I fix CVE-2026-97898?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-97866A weakness has been identified in Zhonglun CloudPOS 3.0. Aff…5.6
- CVE-2026-97868A security vulnerability has been detected in sheshbabu zen …3.5
- CVE-2026-97869A flaw has been found in langchain4j up to 1.5.3-beta10/1.11…4.1
- CVE-2026-9787Quest NetVault Backup NVBULogDaemon Command Injection Remote…8.8
- CVE-2026-97875Rojo's "rojo serve" HTTP API (default port 34872) has no Hos…8.1
- CVE-2026-9789A Local Privilege Escalation (LPE) vulnerability affects Ace…8.5
- CVE-2026-97899In the Linux kernel, the following vulnerability has been re…
- CVE-2026-97900In the Linux kernel, the following vulnerability has been re…
- CVE-2026-97901In the Linux kernel, the following vulnerability has been re…
- CVE-2026-97902In the Linux kernel, the following vulnerability has been re…
- CVE-2026-97903In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-97904In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-97898?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
