Agnaistic agnai through 1.0.555 contains a hard-coded credentials vulnerability in self-host.docker-compose.yml, which sets a fixed admin password and public JWT secret. Unauthenticated attackers can log in as admin or sign their own JWT with admin: true to impersonate users, reset passwords, and change server configuration.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Agnaistic agnai through 1.0.555 contains a hard-coded credentials vulnerability in self-host.docker-compose.yml, which sets a fixed admin password and public JWT secret. Unauthenticated attackers can log in as admin or sign their own JWT with admin: true to impersonate users, reset passwords, and change server configuration. | |
| Title | Agnaistic agnai through 1.0.555 Hard-Coded Credentials in self-host Docker Compose | |
| First Time appeared |
Agnai
Agnai agnai |
|
| Weaknesses | CWE-798 | |
| CPEs | cpe:2.3:a:agnai:agnai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Agnai
Agnai agnai |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T12:19:52.688Z
Reserved: 2026-10-11T01:54:17.948Z
Link: CVE-2026-108753
No data.
Status : Received
Published: 2026-10-11T13:17:20.237
Modified: 2026-10-11T13:17:20.237
Link: CVE-2026-108753
No data.
OpenCVE Enrichment
No data.
Weaknesses