high · CVSS v3 8.4 · CVSS v4 8.6
CVE-2026-94591
Armatura One stores database and message‑broker credentials in an install configuration file encrypted with AES‑128‑CBC. The encryption key
Overview
Armatura One stores database and message‑broker credentials in an install configuration file encrypted with AES‑128‑CBC. The encryption key and IV are hard‑coded and identical across all installations, allowing an attacker who obtains the installation package to decrypt any configuration file. This flaw can expose critical credentials used to access the database and broker.
Description
Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package can recover this key and initialization vector, and can then decrypt the stored credentials of any specific installation to which the attacker separately obtains the encrypted configuration file.
Impact
Confidentiality is compromised as attackers can read stored credentials, potentially gaining full database and broker access. Integrity is at risk if attackers modify configuration files to redirect traffic or inject malicious data. Availability may be impacted if compromised credentials are used to lock out legitimate users. Defenders include database administrators, system integrators, and security teams.
Remediation
1. Apply the vendor‑issued patch that removes hard‑coded keys and implements per‑installation unique keys stored securely. 2. If a patch is unavailable, manually replace the configuration file with one that uses a strong, randomly generated key and IV, and store the key in a protected secrets manager. 3. Restrict access to the installation package and configuration files to authorized personnel only. 4. Monitor for unauthorized access or modifications to configuration files.
Risk context
The vulnerability has a high severity rating (CVSS v3 8.4, v4 8.6) and no EPSS data is available. While the flaw requires the attacker to obtain both the installation package and the encrypted configuration file, the ease of extracting the hard‑coded key makes exploitation straightforward once those prerequisites are met. Defenders should treat this as a significant risk that warrants prompt remediation.
Affected products
- Armatura One
Scores
- Severity
- high
- CVSS v2
- 7.2
- CVSS v3
- 8.4
- CVSS v4
- 8.6
- EPSS
- —