Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-94592— Armatura LLC Armatura One Use of Hard-coded Credentials

Quick assessment

Affected
Armatura LLC Armatura One
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Armatura One 的数据库初始化例程在创建数据库超级用户账户时,会分配一个固定的、由厂商预设的密码,而不是为每次安装生成唯一的密码。任何能够访问服务器操作系统并知晓该固定密码的人,在未修改此密码的部署环境中,都可以以数据库超级用户的身份进行认证登录。

CVSS 8.4 · High

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-94592

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Armatura LLC Armatura One Use of Hard-coded Credentials
Source: CVE Program / CVE List V5
Vulnerability Description
Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用硬编码的凭证
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Armatura LLC Armatura One 0 ~ 4.7.2 -
Armatura LLC Armatura One (USA) 0 ~ 4.6.1 -

II. Public POCs for CVE-2026-94592

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-94592

请登录查看更多情报信息。

Other References for CVE-2026-94592 (2)

Same Patch Batch · Armatura LLC · 2026-10-02 · 4 CVEs total

CVE-2026-94591 8.4 HIGH Armatura LLC Armatura One Use of Hard-coded Cryptographic Key
CVE-2026-94593 7.8 HIGH Armatura LLC Armatura One Insertion of Sensitive Information into Log File
CVE-2026-94594 4.0 MEDIUM Armatura LLC Armatura One Insertion of Sensitive Information into Log File

IV. Related Vulnerabilities

V. Comments for CVE-2026-94592

No comments yet


Leave a comment