CVE-2026-108753

Published: Ott 11, 2026 Last Modified: Ott 11, 2026
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,3
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
CRITICAL 9,4
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: low

Description

AI Translation Available

Agnaistic agnai through 1.0.555 contains a hard-coded credentials vulnerability in self-host.docker-compose.yml, which sets a fixed admin password and public JWT secret. Unauthenticated attackers can log in as admin or sign their own JWT with admin: true to impersonate users, reset passwords, and change server configuration.

798

Use of Hard-coded Credentials

Draft
Common Consequences
Security Scopes Affected:
Access Control Integrity Confidentiality Availability Other
Potential Impacts:
Bypass Protection Mechanism Read Application Data Gain Privileges Or Assume Identity Execute Unauthorized Code Or Commands Other
Applicable Platforms
Technologies: Mobile, ICS/OT
View CWE Details
https://github.com/agnaistic/agnai
https://github.com/agnaistic/agnai/blob/6c3de258cb33999c3f292c71aa031d235268118…
https://github.com/agnaistic/agnai/blob/6c3de258cb33999c3f292c71aa031d235268118…
https://github.com/agnaistic/agnai/blob/6c3de258cb33999c3f292c71aa031d235268118…
https://hackmd.io/@haind/agnai-selfhost-compose-hardcoded-admin-jwt-secret
https://www.vulncheck.com/advisories/agnaistic-agnai-through-1.0.555-hard-coded…