medium · CVSS v3 4 · CVSS v4 5.1
CVE-2026-94594
Armatura One's message broker logs client credentials in plain text, exposing passwords to anyone with log access. This flaw allows attacker
Overview
Armatura One's message broker logs client credentials in plain text, exposing passwords to anyone with log access. This flaw allows attackers to harvest authentication data during normal operation. The vulnerability can lead to credential compromise and unauthorized access.
Description
Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential.
Impact
Confidentiality is compromised as passwords are stored in clear text. Attackers who read logs or backups can obtain valid credentials, enabling unauthorized access to the broker and downstream services. Defenders must treat exposed logs as sensitive data.
Remediation
Apply the vendor's patch that removes credential logging or configures the broker to mask passwords. Restrict log file permissions to privileged users only. Rotate credentials immediately if they may have been exposed. Monitor logs for anomalous access patterns.
Risk context
The issue has a medium severity rating (CVSS v3 4.0, v4 5.1) and no EPSS data. While not critical, the potential for credential theft warrants prompt attention.
Affected products
- Armatura One Message Broker
- Armatura One
Scores
- Severity
- medium
- CVSS v2
- 2.1
- CVSS v3
- 4
- CVSS v4
- 5.1
- EPSS
- —