high · CVSS v3 8.4 · CVSS v4 8.6
CVE-2026-94592
Armatura One's database initialization uses a fixed vendor password for the superuser, allowing anyone with OS access to log in as the datab
Overview
Armatura One's database initialization uses a fixed vendor password for the superuser, allowing anyone with OS access to log in as the database administrator. This flaw can lead to full database compromise on installations where the default password remains unchanged. It is critical for deployments to change the superuser password immediately.
Description
Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed.
Impact
Confidentiality: unauthorized access to all database data. Integrity: attacker can modify or delete data. Availability: potential for denial of service by corrupting database. Defenders: database administrators, system operators, security teams.
Remediation
Change the superuser password to a strong, unique value immediately. Verify that the database initialization script no longer sets a default password. Apply any vendor patches that enforce unique password generation. Restrict OS-level access to the database host and monitor for unauthorized login attempts.
Risk context
Severity is high with CVSS v3 score 8.4. No EPSS data available. Immediate action is recommended to prevent potential full database compromise.
Affected products
- Armatura One
Scores
- Severity
- high
- CVSS v2
- 7.2
- CVSS v3
- 8.4
- CVSS v4
- 8.6
- EPSS
- —