CVE-2026-54445

vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` and password `root`. This is not ideal because attackers know that almost all vantage6 servers have a user with username `root` that probably has admin rights, and the initial password is very weak and it is possible that administrators forget to reset it. Version 5.0.0 fixes the issue. As a workaround, it is possible to delete the `root` user after it has been used to create other users.
CVSS

No CVSS.

Configurations

No configuration.

History

18 Jun 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-17 23:17

Updated : 2026-06-23 15:44


NVD link : CVE-2026-54445

Mitre link : CVE-2026-54445

CVE.ORG link : CVE-2026-54445


JSON object : View

Products Affected

No product.

CWE
CWE-204

Observable Response Discrepancy

CWE-1393

Use of Default Password