CVE-2026-94592

Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed.

  • Published Oct 2, 2026
  • CVSS 8.6 high
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-94592 at the National Vulnerability Database