high · CVSS v3 7.8 · CVSS v4 8.5
CVE-2026-94593
Armatura One's backup routine logs full database connection strings, including superuser passwords, in plain text. This exposes credentials
Overview
Armatura One's backup routine logs full database connection strings, including superuser passwords, in plain text. This exposes credentials to anyone with OS access, enabling unauthorized database access. The flaw can compromise data confidentiality and integrity.
Description
Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available.
Impact
Confidentiality: attackers can obtain superuser credentials, allowing full database access. Integrity: unauthorized changes or deletions can be performed. Availability is not directly affected. Defenders include database administrators and system operators who must secure logs and restrict OS access.
Remediation
Apply the vendor patch that removes passwords from log files. Configure logging to exclude connection strings or use secure logging mechanisms. Restrict OS-level access to the host and rotate logs regularly. Use role-based database access and store credentials in a vault rather than in scripts.
Risk context
Severity is high with CVSS v3 score 7.8 and CVSS v4 score 8.5. No EPSS data is available. The risk is significant for deployments that expose logs to privileged users.
Affected products
- Armatura One Backup
- Armatura One
Scores
- Severity
- high
- CVSS v2
- 6.8
- CVSS v3
- 7.8
- CVSS v4
- 8.5
- EPSS
- —