CVE-2026-94591
Armatura LLC Armatura One Use of Hard-coded Cryptographic Key
CVSS Score
8.4
EPSS Score
0.0%
EPSS Percentile
0th
Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package can recover this key and initialization vector, and can then decrypt the stored credentials of any specific installation to which the attacker separately obtains the encrypted configuration file.
| CWE | CWE-321 |
| Vendor | armatura llc |
| Product | armatura one |
| Published | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for armatura llc armatura one
Be the first to know when new high vulnerabilities affecting armatura llc armatura one are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Armatura LLC / Armatura One
0 < 4.7.2
Armatura LLC / Armatura One (USA)
0 < 4.6.1
References
Credits
Andrew Capobianco of RewCon.co reported this vulnerability to CISA.