MajorCritical vulnerability
CVE-2026-94593 (CVSS 8.5)
NVD · officialPublished Oct 2, 2026Risk 37/100EPSS 0.1%
Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available.
Technical details
CVSS
8.5
AV:LocalAC:LowPR:LowUI:None
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source