Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unlock action is relying on a client-supplied room/door identifier that is not properly authorized server-side against the authenticated guest's booking. An authenticated guest could unlock rooms other than their own, resulting in unauthorized physical access to guest rooms at an affected property.




As of 19th September 2026 the service is no more vulnerable to this attack (feedback received by the reporter). 




The attack is remote but the effect is local to an affected property.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 25 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Description Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unlock action is relying on a client-supplied room/door identifier that is not properly authorized server-side against the authenticated guest's booking. An authenticated guest could unlock rooms other than their own, resulting in unauthorized physical access to guest rooms at an affected property. As of 19th September 2026 the service is no more vulnerable to this attack (feedback received by the reporter).  The attack is remote but the effect is local to an affected property.
Title Broken authorization in Akia keyless entry lets an authenticated guest unlock other rooms
Weaknesses CWE-639
CWE-862
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:H/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-09-25T10:07:35.224Z

Reserved: 2026-09-25T10:07:22.362Z

Link: CVE-2026-97898

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-25T10:17:08.907

Modified: 2026-09-25T10:17:08.907

Link: CVE-2026-97898

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses