CVE-2026-54445 Details
Description
vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` and password `root`. This is not ideal because attackers know that almost all vantage6 servers have a user with username `root` that probably has admin rights, and the initial password is very weak and it is possible that administrators forget to reset it. Version 5.0.0 fixes the issue. As a workaround, it is possible to delete the `root` user after it has been used to create other users.
A vulnerability exists in Vantage6 versions prior to 5.0.0, where the default admin credentials are set to 'root' for both the username and password. This creates a security risk, as it is widely known that Vantage6 servers have a root user with potential admin rights, and the default password is weak. Administrators may forget to change it, leaving the account vulnerable. The issue has been addressed in version 5.0.0, which eliminates the default credentials. As a temporary workaround, the root user can be deleted after creating other user accounts.
Upgrade to Vantage6 version 5.0.0 or later, where this vulnerability has been fixed. If an upgrade is not possible, delete the root user after creating other user accounts.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 17, 2026CISA-ADP
Assessed Jun 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/vantage6/vantage6/blob/main/docs/release_notes.rst#500 | [email protected] | Release NotesVendor |
| https://github.com/vantage6/vantage6/issues/1932 | [email protected] | Issue TrackingVendor |
| https://github.com/vantage6/vantage6/security/advisories/GHSA-fgmc-2hqj-86v4 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1393 | Use of Default Password | [email protected] |
| CWE-204 | Observable Response Discrepancy | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vantage6 | < 4.2.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 18, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | New CVE Received | [email protected] |
Volerion