Armatura One Security Failures Put Access-Control Hosts, Databases, and Credentials at Risk
CISA reports five Armatura One flaws, including unauthenticated ActiveMQ RCE and hardcoded credentials exposing databases, hosts and access control.
Illustrative image generated with AI
CISA has detailed five vulnerabilities in Armatura LLC’s Armatura One platform, including a remotely exploitable Apache ActiveMQ flaw and four weaknesses involving credentials or cryptographic secrets.
The agency initially published ICS advisory ICSA-26-274-01 on October 1, 2026. It covers CVE-2023-46604 and CVE-2026-94591 through CVE-2026-94594.
Depending on the vulnerability, successful exploitation could expose the application database, allow arbitrary code execution with the host operating system’s highest privilege level, or enable control over the physical access-control system.
Armatura One is deployed worldwide. CISA associates the affected installations with the Communications, Critical Manufacturing, Energy, and Transportation Systems sectors. Armatura LLC is headquartered in the United States.
Andrew Capobianco of RewCon.co reported the five issues to CISA.
Two Product Lines Require Different Fixed Releases
All five vulnerabilities affect the following versions, which CISA marks as known affected:
- Armatura One earlier than 4.7.2
- Armatura One (USA) earlier than 4.6.1
The standard product line should be updated to Armatura One V4.7.2. CISA specifically directs customers using V4.7.1 or earlier to install that release.
For the US product line, the fixed version is Armatura One V4.6.1_USA. The corresponding upgrade instruction applies to customers running V4.3.1_USA or earlier.
There is a difference between the affected-version definitions and the narrower upgrade-from wording, particularly for the USA line. The affected range includes every release below 4.6.1, while the explicit instruction names V4.3.1_USA and earlier. The supplied advisory material does not explain that discrepancy.
Customers should identify their precise installed version and contact Armatura’s official technical support for instructions on obtaining and applying the correct update.
Embedded ActiveMQ Opens an Unauthenticated Code-Execution Route
The most severe issue is CVE-2023-46604, an unsafe deserialization vulnerability in the Java OpenWire protocol marshaller used by Apache ActiveMQ.
Armatura One embeds ActiveMQ and, according to CISA, makes its OpenWire listener available on the network by default. A remote attacker can manipulate serialized class types, causing an OpenWire broker or client to instantiate a class available on its classpath.
Crucially, the malicious object graph can be deserialized before authentication is enforced. An attacker with network access therefore needs neither credentials nor user interaction to reach the vulnerable processing path.
In an affected Armatura installation, exploitation can result in arbitrary code running with the highest privilege available on the host operating system.
CISA scores the Armatura exposure at 9.8 under CVSS 3.1, with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Its CVSS 4.0 assessment is 9.3, using CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N.
The broader CVE Program record for the Apache flaw assigns a different CVSS 3.1 score: 10.0, with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H. Both records classify the weakness as CWE-502: Deserialization of Untrusted Data.
The CVE Program lists these affected Apache branches:
- Apache ActiveMQ 5.18.0 before 5.18.3
- Apache ActiveMQ 5.17.0 before 5.17.6
- Apache ActiveMQ 5.16.0 before 5.16.7
- Apache ActiveMQ versions from 0 before 5.15.16
- Apache ActiveMQ Legacy OpenWire Module 5.18.0 before 5.18.3
- Apache ActiveMQ Legacy OpenWire Module 5.17.0 before 5.17.6
- Apache ActiveMQ Legacy OpenWire Module 5.16.0 before 5.16.7
- Apache ActiveMQ Legacy OpenWire Module 5.8.0 before 5.15.16
The recommended fixed Apache versions are 5.15.16, 5.16.7, 5.17.6, or 5.18.3, depending on the branch. Armatura customers, however, have product-level fixes available and should follow Armatura’s supported upgrade process.
Fixed Secrets and Plaintext Logs Create Four More Exposure Paths
The other four vulnerabilities concern how Armatura One generates, encrypts, or records credentials. Their exploitation conditions differ from the network-reachable ActiveMQ flaw.
| Vulnerability | Weakness | CVSS 3.1 | CVSS 4.0 |
|---|---|---|---|
| CVE-2026-94591 | Fixed AES encryption key and initialization vector | 8.4 High | 8.6 High |
| CVE-2026-94592 | Vendor-defined database superuser password | 8.4 High | 8.6 High |
| CVE-2026-94593 | Database password exposed in a host log | 7.8 High | 8.5 High |
| CVE-2026-94594 | Message-broker credentials exposed in logs | 4.0 Medium | 5.1 Medium |
For CVE-2026-94591, Armatura One can encrypt database and message-broker credentials stored in an installation configuration file with AES-128-CBC. The key and initialization vector, however, are fixed inside the software and reused across installations.
An attacker possessing the installation package can recover those cryptographic values. Decrypting credentials from a particular deployment additionally requires access to that installation’s encrypted configuration file. CISA maps the issue to CWE-321: Use of Hard-coded Cryptographic Key.
The CVE Program entry for CVE-2026-94591 remains RESERVED and does not contain a public description, score, or affected-version data. The technical details and ratings currently available here come from CISA’s Armatura advisory.
CVE-2026-94592 affects database initialization. Armatura One assigns a fixed, vendor-defined password to the database superuser instead of creating a unique credential for each installation. A person who knows that value and can access the server operating system could authenticate as the superuser if the password remains unchanged. CISA classifies this as CWE-798: Use of Hard-coded Credentials.
Under CVE-2026-94593, the backup-and-restore process writes the complete database connection command to a host log. That command contains the superuser password in plaintext. The exposed credential can be used to access the database when the attacker also has access to the server operating system.
CVE-2026-94594 affects the message broker during normal operation. Client connection credentials, including the password, are written to a plaintext log. Anyone able to read that file—or a backup or support bundle containing it—can recover the logged credential.
CISA assigns both logging flaws CWE-532: Insertion of Sensitive Information into Log File.
One Vulnerability Is Already Known to Be Exploited
CISA says it “is not aware of exploitation specifically targeting Armatura One in relation to these vulnerabilities.” That statement is limited to the agency’s awareness of Armatura-specific targeting; it does not establish that no such activity occurred.
The underlying ActiveMQ vulnerability has a stronger exploitation record. CVE-2023-46604 entered CISA’s Known Exploited Vulnerabilities catalog on 2023-11-02, and it has been used in ransomware campaigns against other Apache ActiveMQ deployments.
US federal agencies received a remediation deadline of 2023-11-23. CISA’s required action is to apply mitigations according to vendor instructions or discontinue use when mitigations are unavailable.
Separate archive records show three KEV additions during the last 90 days involving vendors also represented in the wider CVE-2023-46604 product data: CVE-2025-39682 on 2026-09-18, CVE-2022-0995 on 2026-08-26, and CVE-2026-34486 on 2026-08-04, associated with Debian, NetApp, or Apache. These records provide vendor-tracking context but do not demonstrate any connection to Armatura exploitation.
Immediate Priorities for Armatura One Operators
The primary product-specific remedy is straightforward:
- Install Armatura One V4.7.2 for the standard release line.
- Install Armatura One V4.6.1_USA for the USA release line.
- Obtain deployment guidance from Armatura’s official technical support.
Operators should also determine whether the default OpenWire listener is reachable from untrusted networks. CISA recommends minimizing the network exposure of control-system equipment, keeping such systems off the public internet, and placing operational environments behind firewalls with separation from business networks.
If remote connectivity is necessary, CISA recommends using a VPN, maintaining it at the newest available version, and considering the security of every connected endpoint. Organizations should perform impact and risk assessments before changing access-control infrastructure.
Because several findings involve configuration files, host logs, backups, and support bundles, defensive reviews should account for who can access those assets and where copies are retained. The supplied advisory material does not identify vulnerability-specific indicators for these issues.
Organizations that detect suspected malicious activity should follow their established incident-response procedures and report their findings to CISA for correlation with other incidents.
Sources
This article is an original reworking based on the sources below.
- primary sourceCVE Program
- primary sourceCVE Program
- CISA Advisories




