<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 09:39:27 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-328554</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-328554</link>
      <description>EUVD-2026-328554</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-328554</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54445</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54445</link>
      <description>&lt;p&gt;vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` and password `root`. This is not ideal because attackers know that almost all vantage6 servers have a user with username `root` that probably has admin rights, and the initial password is very weak and it is possible that administrators forget to reset it. Version 5.0.0 fixes the issue. As a workaround, it is possible to delete the `root` user after it has been used to create other users.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` and password `root`. This is not ideal because attackers know that almost all vantage6 servers have a user with username `root` that probably has admin rights, and the initial password is very weak and it is possible that administrators forget to reset it. Version 5.0.0 fixes the issue. As a workaround, it is possible to delete the `root` user after it has been used to create other users.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54445</guid>
    </item>
    <item>
      <title>GHSA-fgmc-2hqj-86v4 — Vantage6: Set admin user and password from environment or configuration</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fgmc-2hqj-86v4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vantage6&lt;/p&gt;
&lt;p&gt;### Impact
Vantage6 currently provides an initial user with username `root` and password `root`. This is not ideal for the following reasons:
- Attackers know that almost all vantage6 servers have a user with username `root` that probably has admin rights
- The initial password is very weak and it is possible that administrators forget to reset it.&lt;/p&gt;
&lt;p&gt;### Patches
No&lt;/p&gt;
&lt;p&gt;### Workarounds
It is possible to delete the `root` user after it has been used to create other users&lt;/p&gt;
&lt;p&gt;### References
We could consider doing this like [mongodb](https://hub.docker.com/_/mongo)&lt;/p&gt;
&lt;p&gt;### Additional info&lt;/p&gt;
&lt;p&gt;Luis uses the following patch to mitigate it:
```diff
diff --git a/vantage6-server/vantage6/server/__init__.py b/vantage6-server/vantage6/server/__init__.py
index ea362c1e..c6dcbbd9 100644
--- a/vantage6-server/vantage6/server/__init__.py
+++ b/vantage6-server/vantage6/server/__init__.py
@@ -618,18 +618,30 @@ class ServerApp:
             # TODO use constant instead of &amp;#39;Root&amp;#39; literal
             root = db.Role.get_by_name(&amp;#34;Root&amp;#34;)
 
-            log.warn(
-                f&amp;#34;Creating root user: &amp;#34;
-                f&amp;#34;username={SUPER_USER_INFO[&amp;#39;username&amp;#39;]}, &amp;#34;
-                f&amp;#34;password={SUPER_USER_INFO[&amp;#39;password&amp;#39;]}&amp;#34;
-            )
+            # Temporary patch
+            # read initial root password from file (docker secret) if provided
+            # TODO: This is a workaround so we don&amp;#39;t have an insecure vserver
+            #       at the start. Ideally, we would provide an already hashed
+…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vantage6&lt;/p&gt;
&lt;p&gt;### Impact
Vantage6 currently provides an initial user with username `root` and password `root`. This is not ideal for the following reasons:
- Attackers know that almost all vantage6 servers have a user with username `root` that probably has admin rights
- The initial password is very weak and it is possible that administrators forget to reset it.&lt;/p&gt;
&lt;p&gt;### Patches
No&lt;/p&gt;
&lt;p&gt;### Workarounds
It is possible to delete the `root` user after it has been used to create other users&lt;/p&gt;
&lt;p&gt;### References
We could consider doing this like [mongodb](https://hub.docker.com/_/mongo)&lt;/p&gt;
&lt;p&gt;### Additional info&lt;/p&gt;
&lt;p&gt;Luis uses the following patch to mitigate it:
```diff
diff --git a/vantage6-server/vantage6/server/__init__.py b/vantage6-server/vantage6/server/__init__.py
index ea362c1e..c6dcbbd9 100644
--- a/vantage6-server/vantage6/server/__init__.py
+++ b/vantage6-server/vantage6/server/__init__.py
@@ -618,18 +618,30 @@ class ServerApp:
             # TODO use constant instead of &amp;#39;Root&amp;#39; literal
             root = db.Role.get_by_name(&amp;#34;Root&amp;#34;)
 
-            log.warn(
-                f&amp;#34;Creating root user: &amp;#34;
-                f&amp;#34;username={SUPER_USER_INFO[&amp;#39;username&amp;#39;]}, &amp;#34;
-                f&amp;#34;password={SUPER_USER_INFO[&amp;#39;password&amp;#39;]}&amp;#34;
-            )
+            # Temporary patch
+            # read initial root password from file (docker secret) if provided
+            # TODO: This is a workaround so we don&amp;#39;t have an insecure vserver
+            #       at the start. Ideally, we would provide an already hashed
+…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fgmc-2hqj-86v4</guid>
    </item>
    <item>
      <title>PYSEC-2026-3400 — Vantage6: Set admin user and password from environment or configuration</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3400</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vantage6&lt;/p&gt;
&lt;p&gt;### Impact
Vantage6 currently provides an initial user with username `root` and password `root`. This is not ideal for the following reasons:
- Attackers know that almost all vantage6 servers have a user with username `root` that probably has admin rights
- The initial password is very weak and it is possible that administrators forget to reset it.&lt;/p&gt;
&lt;p&gt;### Patches
No&lt;/p&gt;
&lt;p&gt;### Workarounds
It is possible to delete the `root` user after it has been used to create other users&lt;/p&gt;
&lt;p&gt;### References
We could consider doing this like [mongodb](https://hub.docker.com/_/mongo)&lt;/p&gt;
&lt;p&gt;### Additional info&lt;/p&gt;
&lt;p&gt;Luis uses the following patch to mitigate it:
```diff
diff --git a/vantage6-server/vantage6/server/__init__.py b/vantage6-server/vantage6/server/__init__.py
index ea362c1e..c6dcbbd9 100644
--- a/vantage6-server/vantage6/server/__init__.py
+++ b/vantage6-server/vantage6/server/__init__.py
@@ -618,18 +618,30 @@ class ServerApp:
             # TODO use constant instead of &amp;#39;Root&amp;#39; literal
             root = db.Role.get_by_name(&amp;#34;Root&amp;#34;)
 
-            log.warn(
-                f&amp;#34;Creating root user: &amp;#34;
-                f&amp;#34;username={SUPER_USER_INFO[&amp;#39;username&amp;#39;]}, &amp;#34;
-                f&amp;#34;password={SUPER_USER_INFO[&amp;#39;password&amp;#39;]}&amp;#34;
-            )
+            # Temporary patch
+            # read initial root password from file (docker secret) if provided
+            # TODO: This is a workaround so we don&amp;#39;t have an insecure vserver
+            #       at the start. Ideally, we would provide an already hashed
+…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vantage6&lt;/p&gt;
&lt;p&gt;### Impact
Vantage6 currently provides an initial user with username `root` and password `root`. This is not ideal for the following reasons:
- Attackers know that almost all vantage6 servers have a user with username `root` that probably has admin rights
- The initial password is very weak and it is possible that administrators forget to reset it.&lt;/p&gt;
&lt;p&gt;### Patches
No&lt;/p&gt;
&lt;p&gt;### Workarounds
It is possible to delete the `root` user after it has been used to create other users&lt;/p&gt;
&lt;p&gt;### References
We could consider doing this like [mongodb](https://hub.docker.com/_/mongo)&lt;/p&gt;
&lt;p&gt;### Additional info&lt;/p&gt;
&lt;p&gt;Luis uses the following patch to mitigate it:
```diff
diff --git a/vantage6-server/vantage6/server/__init__.py b/vantage6-server/vantage6/server/__init__.py
index ea362c1e..c6dcbbd9 100644
--- a/vantage6-server/vantage6/server/__init__.py
+++ b/vantage6-server/vantage6/server/__init__.py
@@ -618,18 +618,30 @@ class ServerApp:
             # TODO use constant instead of &amp;#39;Root&amp;#39; literal
             root = db.Role.get_by_name(&amp;#34;Root&amp;#34;)
 
-            log.warn(
-                f&amp;#34;Creating root user: &amp;#34;
-                f&amp;#34;username={SUPER_USER_INFO[&amp;#39;username&amp;#39;]}, &amp;#34;
-                f&amp;#34;password={SUPER_USER_INFO[&amp;#39;password&amp;#39;]}&amp;#34;
-            )
+            # Temporary patch
+            # read initial root password from file (docker secret) if provided
+            # TODO: This is a workaround so we don&amp;#39;t have an insecure vserver
+            #       at the start. Ideally, we would provide an already hashed
+…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3400</guid>
    </item>
  </channel>
</rss>
