CVE-2026-94592: Armatura Llc Armatura One
High severity, CVSS 8.4. EPSS: 0.1% chance of exploitation in the next 30 days.
Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed.
Affected products
- Armatura Llc Armatura One: before 4.7.2 (fixed in 4.7.2)
- Armatura Llc Armatura One Usa: before 4.6.1 (fixed in 4.6.1)
Published 2026-10-02. Last modified 2026-10-06.