ICSA-26-274-01: Armatura LLC Armatura One
CISA advisory · released 2026-10-01
Source record Collected from CISA's CSAF advisory feed
- Distribution label in the document: TLP:WHITE
- Revision 1, 2026-10-01 (final)
CISA's summary
Advisory Summary: Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system.
Products, as the advisory lists them
| Vendor | Product | Version |
|---|---|---|
| Armatura LLC | Armatura One | <4.7.2 |
| Armatura LLC | Armatura One (USA) | <4.6.1 |
DeSpy has not checked any unit, hardware revision or firmware.
Vulnerabilities in this advisory
- CVE-2023-46604 · CWE-502
Armatura One embeds Apache ActiveMQ, exposing its OpenWire protocol listener on the network by default. This embedded version is affected by CVE-2023-46604, a deserialization flaw in the OpenWire marshaller that allows an unauthenticated network attacker to trigger deserialization of an arbitrary object graph before authentication is checked. This can result in arbitrary code execution with the highest level of privilege on the host operating system.
- CVE-2026-94591 · CWE-321
Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package can recover this key and initialization vector, and can then decrypt the stored credentials of any specific installation to which the attacker separately obtains the encrypted configuration file.
- CVE-2026-94592 · CWE-798
Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed.
- CVE-2026-94593 · CWE-532
Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available.
- CVE-2026-94594 · CWE-532
Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential.
Acknowledgments, as the advisory lists them
- Andrew Capobianco, RewCon.co: reported these vulnerabilities to CISA
The advisory's legal notice
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Sources
DeSpy's copy of this version is dated 2026-10-01.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.