CVE-2026-94594

Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential.

  • Published Oct 2, 2026
  • CVSS 5.1 medium
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-94594 at the National Vulnerability Database