Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-94594— Armatura LLC Armatura One Insertion of Sensitive Information into Log File

Quick assessment

Affected
Armatura LLC Armatura One
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Armatura One 的消息代理在正常运行过程中,会以明文形式记录客户端连接的凭据及其关联的密码。任何拥有日志读取权限,或拥有包含该日志的备份或支持包的各方,均可以获取已记录的凭据。

CVSS 4.0 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-94594

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Armatura LLC Armatura One Insertion of Sensitive Information into Log File
Source: CVE Program / CVE List V5
Vulnerability Description
Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过日志文件的信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Armatura LLC Armatura One 0 ~ 4.7.2 -
Armatura LLC Armatura One (USA) 0 ~ 4.6.1 -

II. Public POCs for CVE-2026-94594

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-94594

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-94594 (2)

Same Patch Batch · Armatura LLC · 2026-10-02 · 4 CVEs total

CVE-2026-94592 8.4 HIGH Armatura LLC Armatura One Use of Hard-coded Credentials
CVE-2026-94591 8.4 HIGH Armatura LLC Armatura One Use of Hard-coded Cryptographic Key
CVE-2026-94593 7.8 HIGH Armatura LLC Armatura One Insertion of Sensitive Information into Log File

IV. Related Vulnerabilities

V. Comments for CVE-2026-94594

No comments yet


Leave a comment