CVE-2026-108753
CRITICAL
9,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
CRITICAL
9,4
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: low
Description
AI Translation Available
Agnaistic agnai through 1.0.555 contains a hard-coded credentials vulnerability in self-host.docker-compose.yml, which sets a fixed admin password and public JWT secret. Unauthenticated attackers can log in as admin or sign their own JWT with admin: true to impersonate users, reset passwords, and change server configuration.
798
Use of Hard-coded Credentials
DraftCommon Consequences
Security Scopes Affected:
Access Control
Integrity
Confidentiality
Availability
Other
Potential Impacts:
Bypass Protection Mechanism
Read Application Data
Gain Privileges Or Assume Identity
Execute Unauthorized Code Or Commands
Other
Applicable Platforms
Technologies:
Mobile, ICS/OT
https://github.com/agnaistic/agnai
https://github.com/agnaistic/agnai/blob/6c3de258cb33999c3f292c71aa031d235268118…
https://github.com/agnaistic/agnai/blob/6c3de258cb33999c3f292c71aa031d235268118…
https://github.com/agnaistic/agnai/blob/6c3de258cb33999c3f292c71aa031d235268118…
https://hackmd.io/@haind/agnai-selfhost-compose-hardcoded-admin-jwt-secret
https://www.vulncheck.com/advisories/agnaistic-agnai-through-1.0.555-hard-coded…