CVE-2025-59096: Dormakaba Kaba Exos 9300

Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.

The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is hard-coded in multiple locations as well as documented in the locally stored user documentation.

Affected products

Published 2026-01-26. Last modified 2026-06-17.