CVE-2026-94592: Armatura LLC Armatura One Use of Hard-coded Credentials
Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Armatura One USAto a version that resolves this vulnerability.Fixed in V4.6.1_USA - Upgrade
Upgrade
Armatura Oneto a version that resolves this vulnerability.Fixed in V4.7.2
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Deployments are exposed when the database superuser password remains at the vendor-defined value. Exploitation also requires access to the server operating system and knowledge of that password.
Is remote network access alone sufficient to exploit this issue?
The available information specifies that an attacker needs access to the server operating system. It does not indicate that remote network access alone is sufficient.
How can I determine whether my deployment is affected?
Check whether the database superuser account created during initialization still uses the fixed vendor-defined password. A deployment where that password has been changed is not described as affected by this condition.
What can be done if remediation cannot be applied immediately?
Change the database superuser password from the vendor-defined value and restrict access to the server operating system.