rootpwn

high · CVSS v3 8.4 · CVSS v4 8.6

CVE-2026-94592

Armatura One's database initialization uses a fixed vendor password for the superuser, allowing anyone with OS access to log in as the datab

Overview

Armatura One's database initialization uses a fixed vendor password for the superuser, allowing anyone with OS access to log in as the database administrator. This flaw can lead to full database compromise on installations where the default password remains unchanged. It is critical for deployments to change the superuser password immediately.

Description

Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed.

Impact

Confidentiality: unauthorized access to all database data. Integrity: attacker can modify or delete data. Availability: potential for denial of service by corrupting database. Defenders: database administrators, system operators, security teams.

Remediation

Change the superuser password to a strong, unique value immediately. Verify that the database initialization script no longer sets a default password. Apply any vendor patches that enforce unique password generation. Restrict OS-level access to the database host and monitor for unauthorized login attempts.

Risk context

Severity is high with CVSS v3 score 8.4. No EPSS data available. Immediate action is recommended to prevent potential full database compromise.

Affected products

  • Armatura One

Scores

Severity
high
CVSS v2
7.2
CVSS v3
8.4
CVSS v4
8.6
EPSS
—

database default-password privilege-escalation ArmaturaOne superuser credential-guessing patch configuration

← All CVEs