dormakaba Access Manager Unauthenticated SOAP API Vulnerability Allowing Arbitrary Door Control

Vulnerability

A critical vulnerability has been identified in the dormakaba Access Manager 9200-k5 and 9200-k7 hardware revisions, prior to the latest firmware updates. The issue lies in an unauthenticated SOAP API that allows attackers to manipulate the access manager's configuration and control connected devices, including opening doors and deactivating security inputs. This vulnerability can be exploited remotely, provided the attacker has network access to the access manager.

Impact

Exploitation of this vulnerability allows for unauthorized access control, including opening doors and reconfiguring the access manager's settings. This could lead to unauthorized entry into secured areas.

Reproduction

The vulnerability can be reproduced by sending a SOAP request to the access manager's API on port 8002. The request must include the identifier of the access manager and the command to be executed, such as opening a door or changing a configuration parameter. This can be done using a simple script or a tool like Burp Suite to automate the process.

Remediation

Users are advised to update to the latest firmware version and consult with their dormakaba partner for guidance on implementing the necessary security measures.

Added: Jan 26, 2026, 10:34 AM
Updated: Jan 26, 2026, 3:16 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.2
remediation
0.0
relevance
2.4
threat
1.6
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.