CVE-2026-94594

Summary

Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential.

Affected Software

VendorProductVersion RangeStatus
Armatura LLCArmatura One0 < 4.7.2affected
Armatura LLCArmatura One4.7.2unaffected
Armatura LLCArmatura One (USA)0 < 4.6.1affected
Armatura LLCArmatura One (USA)4.6.1_USAunaffected

Weaknesses

  • CWE-532: CWE-532

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References