CVE-2026-94593

Summary

Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available.

Affected Software

VendorProductVersion RangeStatus
Armatura LLCArmatura One0 < 4.7.2affected
Armatura LLCArmatura One4.7.2unaffected
Armatura LLCArmatura One (USA)0 < 4.6.1affected
Armatura LLCArmatura One (USA)4.6.1_USAunaffected

Weaknesses

  • CWE-532: CWE-532

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References