CVE-2026-94591: Armatura LLC Armatura One Use of Hard-coded Cryptographic Key
Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package can recover this key and initialization vector, and can then decrypt the stored credentials of any specific installation to which the attacker separately obtains the encrypted configuration file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Armatura Oneto a version that resolves this vulnerability.Fixed in V4.6.1_USA - Upgrade
Upgrade
Armatura Oneto a version that resolves this vulnerability.Fixed in V4.7.2
Event History
Frequently Asked Questions
What must an attacker obtain to decrypt the protected credentials?
The attacker needs both a copy of the Armatura One installation package, which contains the fixed AES-128-CBC key and initialization vector, and the encrypted install configuration file from the targeted installation.
Are credentials encrypted by different installations protected by different keys?
No. The encryption key and initialization vector are embedded in the software and are identical across every installation, so recovering them from any installation package enables decryption of encrypted configuration files obtained from other installations.
Which credentials are at risk if the encrypted configuration file is exposed?
The installation configuration file stores database and message-broker credentials. If an attacker obtains that encrypted file and the installation package, those credentials can be decrypted.