Database Vulnerability in Armatura One's Backup and Restore Routine
CVE-2026-94593
8.5HIGH
What is CVE-2026-94593?
The Armatura One product's backup and restore routine has a significant security flaw, where it logs the complete database connection command, including the superuser password, in a plain text format. This unprotected information is stored in a log file on the host, which, if accessed by an unauthorized user or attacker, could lead to the compromised database. The exposed credentials pose a serious risk, especially if the attacker gains access to the server operating system, allowing for malicious database activities.
Affected Version(s)
Armatura One 0 < 4.7.2
Armatura One (USA) 0 < 4.6.1
Armatura One 4.7.2
References
CVSS V4
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Andrew Capobianco of RewCon.co reported this vulnerability to CISA.
