Description
Agnaistic agnai through 1.0.555 contains a hard-coded credentials vulnerability in self-host.docker-compose.yml, which sets a fixed admin password and public JWT secret. Unauthenticated attackers can log in as admin or sign their own JWT with admin: true to impersonate users, reset passwords, and change server configuration.
Published: 2026-10-11
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Unauthorized admin access via hard‑coded credentials
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exposes a fixed admin password and a public JWT secret in the self‑host docker‑compose.yml file of Agnaistic agnai. An unauthenticated attacker can log in as administrator or forge a token with admin privileges, gaining full control over the server. This allows resetting arbitrary user passwords, modifying configuration, and potentially compromising confidentiality, integrity and availability.

Affected Systems

Agnaistic agnai versions up to and including 1.0.555 contain hard‑coded credentials in the docker‑compose.yml file. Any deployment that uses the default configuration or older releases is susceptible unless the user replaces the hard‑coded password and JWT secret with unique values before deployment.

Risk and Exploitability

The CVSS score of 9.3 denotes critical severity. EPSS is not available but the attack is straightforward: an attacker with network access to the deployed service can exploit the static credentials without complex steps. The vulnerability is not listed in CISA KEV, yet the combination of easy exploitation and full administrative takeover yields a high risk.

Generated by OpenCVE AI on October 11, 2026 at 14:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Replace the hard‑coded admin password and JWT secret in self‑host.docker-compose.yml with secure, randomly generated values before the service starts.
  • Deploy a newer release of Agnaistic agnai that has removed the hard‑coded credentials; if unavailable, reconfigure the application to load credentials from environment variables or a secure vault.
  • Enforce a strong password policy for new admin accounts and audit the deployment to confirm that no default values persist.

Generated by OpenCVE AI on October 11, 2026 at 14:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Agnaistic agnai through 1.0.555 contains a hard-coded credentials vulnerability in self-host.docker-compose.yml, which sets a fixed admin password and public JWT secret. Unauthenticated attackers can log in as admin or sign their own JWT with admin: true to impersonate users, reset passwords, and change server configuration.
Title Agnaistic agnai through 1.0.555 Hard-Coded Credentials in self-host Docker Compose
First Time appeared Agnai
Agnai agnai
Weaknesses CWE-798
CPEs cpe:2.3:a:agnai:agnai:*:*:*:*:*:*:*:*
Vendors & Products Agnai
Agnai agnai
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:52.688Z

Reserved: 2026-10-11T01:54:17.948Z

Link: CVE-2026-108753

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:20.237

Modified: 2026-10-11T13:17:20.237

Link: CVE-2026-108753

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:15:18Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials