- Sources: primary, discussion
- Summary: The writeup describes an attack chain against Paxton10 access control systems that begins with credentials hardcoded and shared across installations. Those credentials reach a support portal that serves nginx access logs recording bearer tokens in plaintext, and a stolen token authenticates a SQL injection through an escaping routine applied in the wrong direction, which becomes operating system command execution because the product installer enables xp_cmdshell and grants the service accounts sysadmin on the database server. The author tracks the defects as CAN-2026-2032786 for the hardcoded log portal credentials and CAN-2026-2032789 for the post-authentication SQL injection, notes both are CAN rather than confirmed CVE identifiers, and states versions prior to Paxton10 4.9 SR12 are affected, with Paxton releasing that version on 2026-06-24 after reports on 2026-06-05 and 2026-06-08 and confirming the fix on 2026-06-25.
- Why it matters: The installer turns on xp_cmdshell and grants the service accounts sysadmin on every install, so any SQL injection in the application is operating system command execution by construction.
send feedback on this story