<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T17:03:32.950805+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-54445</id>
    <title>CVE-2026-54445 — Vantage6: Set admin user and password from environment or configuration</title>
    <updated>2026-10-04T17:03:32.952528+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> vantage6</p>
<p>vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` and password `root`. This is not ideal because attackers know that almost all vantage6 servers have a user with username `root` that probably has admin rights, and the initial password is very weak and it is possible that administrators forget to reset it. Version 5.0.0 fixes the issue. As a workaround, it is possible to delete the `root` user after it has been used to create other users.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-54445"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fgmc-2hqj-86v4</id>
    <title>GHSA-fgmc-2hqj-86v4 — Vantage6: Set admin user and password from environment or configuration</title>
    <updated>2026-10-04T17:03:32.952590+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vantage6</p>
<p>### Impact
Vantage6 currently provides an initial user with username `root` and password `root`. This is not ideal for the following reasons:
- Attackers know that almost all vantage6 servers have a user with username `root` that probably has admin rights
- The initial password is very weak and it is possible that administrators forget to reset it.</p>
<p>### Patches
No</p>
<p>### Workarounds
It is possible to delete the `root` user after it has been used to create other users</p>
<p>### References
We could consider doing this like [mongodb](https://hub.docker.com/_/mongo)</p>
<p>### Additional info</p>
<p>Luis uses the following patch to mitigate it:
```diff
diff --git a/vantage6-server/vantage6/server/__init__.py b/vantage6-server/vantage6/server/__init__.py
index ea362c1e..c6dcbbd9 100644
--- a/vantage6-server/vantage6/server/__init__.py
+++ b/vantage6-server/vantage6/server/__init__.py
@@ -618,18 +618,30 @@ class ServerApp:
             # TODO use constant instead of 'Root' literal
             root = db.Role.get_by_name("Root")
 
-            log.warn(
-                f"Creating root user: "
-                f"username={SUPER_USER_INFO['username']}, "
-                f"password={SUPER_USER_INFO['password']}"
-            )
+            # Temporary patch
+            # read initial root password from file (docker secret) if provided
+            # TODO: This is a workaround so we don't have an insecure vserver
+            #       at the start. Ideally, we would provide an already hashed
+…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fgmc-2hqj-86v4"/>
  </entry>
</feed>
