CVE-2026-94592

Summary

Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed.

Affected Software

VendorProductVersion RangeStatus
Armatura LLCArmatura One0 < 4.7.2affected
Armatura LLCArmatura One4.7.2unaffected
Armatura LLCArmatura One (USA)0 < 4.6.1affected
Armatura LLCArmatura One (USA)4.6.1_USAunaffected

Weaknesses

  • CWE-798: CWE-798

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References