Security Flaw in Armatura One's Message Broker Exposes Client Credentials
CVE-2026-94594
5.1MEDIUM
What is CVE-2026-94594?
A critical flaw in Armatura One's message broker has been identified, where client connection credentials, including passwords, are logged in plain text. During normal operation, this logging occurs, allowing unauthorized individuals with access to the logs, backups, or support bundles to retrieve sensitive information. This vulnerability poses a significant risk to the confidentiality of client data and necessitates urgent review and mitigation strategies to safeguard against unauthorized access.
Affected Version(s)
Armatura One 0 < 4.7.2
Armatura One (USA) 0 < 4.6.1
Armatura One 4.7.2
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Andrew Capobianco of RewCon.co reported this vulnerability to CISA.
