CVE-2026-54445 PUBLISHED

Vantage6: Set admin user and password from environment or configuration

Assigner: GitHub_M
Reserved: 15.06.2026 Published: 17.06.2026 Updated: 17.06.2026

vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username root and password root. This is not ideal because attackers know that almost all vantage6 servers have a user with username root that probably has admin rights, and the initial password is very weak and it is possible that administrators forget to reset it. Version 5.0.0 fixes the issue. As a workaround, it is possible to delete the root user after it has been used to create other users.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor vantage6
Product vantage6
Versions
  • Version < 5.0.0 is affected

References

Problem Types

  • CWE-204: Observable Response Discrepancy CWE
  • CWE-1393: Use of Default Password CWE