CVE-2026-94591: Armatura LLC Armatura One Use of Hard-coded Cryptographic Key

Published Oct 2, 2026
·
Updated

Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package can recover this key and initialization vector, and can then decrypt the stored credentials of any specific installation to which the attacker separately obtains the encrypted configuration file.

Affected Software

1 affected component
Armatura LLC Armatura One

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Armatura One to a version that resolves this vulnerability.

    Fixed in V4.6.1_USA
  2. Upgrade

    Upgrade Armatura One to a version that resolves this vulnerability.

    Fixed in V4.7.2

Event History

Oct 2, 2026
CVE Published
via MITRE·09:54 PM
Data Sourced
via MITRE·09:54 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

What must an attacker obtain to decrypt the protected credentials?

The attacker needs both a copy of the Armatura One installation package, which contains the fixed AES-128-CBC key and initialization vector, and the encrypted install configuration file from the targeted installation.

2

Are credentials encrypted by different installations protected by different keys?

No. The encryption key and initialization vector are embedded in the software and are identical across every installation, so recovering them from any installation package enables decryption of encrypted configuration files obtained from other installations.

3

Which credentials are at risk if the encrypted configuration file is exposed?

The installation configuration file stores database and message-broker credentials. If an attacker obtains that encrypted file and the installation package, those credentials can be decrypted.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203