CVE-2026-94594
Received Received - Intake

Armatura One Message Broker Plaintext Credential Logging

Vulnerability report for CVE-2026-94594, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: ICS-CERT

Description

Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Armatura One's message broker logs client connection credentials and passwords in plain text during normal operation. This means sensitive authentication details are stored without encryption, making them accessible to anyone with log access.

Detection Guidance

Check log files for plaintext credentials in Armatura One's message broker logs. Search for password patterns or connection credentials in log directories or support bundles. Use commands like grep to scan log files for sensitive data.

Impact Analysis

Attackers or unauthorized users with access to logs or backups could steal credentials, leading to unauthorized system access, data breaches, or further exploitation of connected services.

Compliance Impact

This vulnerability likely violates GDPR (data protection) and HIPAA (health data security) due to unauthorized access risks and failure to protect sensitive credentials in logs.

Mitigation Strategies

Disable plaintext logging for credentials in Armatura One's message broker configuration. Rotate all exposed credentials immediately. Restrict access to log files and support bundles containing sensitive data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94594. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart