Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fgmc-2hqj-86v4 | Vantage6: Set admin user and password from environment or configuration |
Thu, 18 Jun 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vantage6
Vantage6 vantage6 |
|
| Vendors & Products |
Vantage6
Vantage6 vantage6 |
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` and password `root`. This is not ideal because attackers know that almost all vantage6 servers have a user with username `root` that probably has admin rights, and the initial password is very weak and it is possible that administrators forget to reset it. Version 5.0.0 fixes the issue. As a workaround, it is possible to delete the `root` user after it has been used to create other users. | |
| Title | Vantage6: Set admin user and password from environment or configuration | |
| Weaknesses | CWE-1393 CWE-204 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-18T15:49:54.097Z
Reserved: 2026-06-15T15:30:40.317Z
Link: CVE-2026-54445
Updated: 2026-06-18T15:49:50.541Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-18T21:00:13Z
Github GHSA