CVE-2026-94594: Armatura LLC Armatura One Insertion of Sensitive Information into Log File
Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Armatura Oneto a version that resolves this vulnerability.Fixed in V4.6.1_USA - Upgrade
Upgrade
Armatura Oneto a version that resolves this vulnerability.Fixed in V4.7.2
Event History
Frequently Asked Questions
Who can obtain the exposed credentials?
Any party with read access to the message broker log can obtain the client connection credential and password. This also includes parties who can access backups or support bundles containing the log.
Does exploitation require interacting with the message broker?
No. The credentials are written in plain text during normal operation, so an attacker needs read access to the relevant log, backup, or support bundle rather than the ability to initiate a broker connection.
What should be reviewed to determine whether credentials may already be exposed?
Review access to message broker logs and identify backups or support bundles that include those logs. Anyone who could read those artifacts may have been able to obtain the logged credentials.