Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 11 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Agnaistic agnai through 1.0.555 contains a hard-coded credentials vulnerability in self-host.docker-compose.yml, which sets a fixed admin password and public JWT secret. Unauthenticated attackers can log in as admin or sign their own JWT with admin: true to impersonate users, reset passwords, and change server configuration. | |
| Title | Agnaistic agnai through 1.0.555 Hard-Coded Credentials in self-host Docker Compose | |
| First Time appeared |
Agnai
Agnai agnai |
|
| Weaknesses | CWE-798 | |
| CPEs | cpe:2.3:a:agnai:agnai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Agnai
Agnai agnai |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T12:19:52.688Z
Reserved: 2026-10-11T01:54:17.948Z
Link: CVE-2026-108753
No data.
Status : Received
Published: 2026-10-11T13:17:20.237
Modified: 2026-10-11T13:17:20.237
Link: CVE-2026-108753
No data.
OpenCVE Enrichment
No data.
-
CWE-798
Use of Hard-coded Credentials