Skip to content
Threat Feed
medium advisory

Hard-coded Credentials in Agnaistic Agnai

Agnaistic Agnai versions 1.0.555 and earlier contain hard-coded administrative credentials and a static JWT secret, enabling unauthenticated account takeover and configuration manipulation.

CVE search metadata

CVE search record: CVE-2026-108753. Severity: critical. CVSS: 9.4. KEV: no. Product: agnai (<= 1.0.555). Brief: Hard-coded Credentials in Agnaistic Agnai. Brief link: https://feed.craftedsignal.io/briefs/2026-10-agnai-hardcoded-creds/

Agnaistic Agnai through version 1.0.555 is vulnerable to a hard-coded credentials flaw originating from the self-host.docker-compose.yml file. This configuration file ships with a fixed, publicly known administrative password and a static JWT signing secret. Because these secrets are predictable and embedded within the distribution's configuration template, any deployment using the default settings is susceptible to full administrative compromise by an unauthenticated attacker. This flaw allows malicious actors to authenticate as the administrator, generate forged JSON Web Tokens (JWTs) with administrative claims, perform unauthorized password resets, and gain complete control over the server configuration. The vulnerability is rated with a CVSS v3.1 base score of 9.4, highlighting the significant risk to deployments that do not explicitly rotate these secrets upon initial configuration.

Impact

Successful exploitation allows unauthenticated attackers to obtain full administrative control over the affected Agnai server. This grants the attacker the ability to manage all user accounts, modify server-wide settings, and access potentially sensitive data stored within the application instance. Organizations relying on default deployment configurations are at immediate risk of total service compromise.

Recommendation

Prioritize remediation for all deployments of Agnai version 1.0.555 and earlier.

  • Audit all current Agnai deployments to determine if default credentials or the default JWT secret are in use.
  • Update to a version where these credentials are no longer hard-coded or manually rotate the admin password and JWT secret immediately.
  • Restrict network access to administrative interfaces to trusted IP addresses until secrets are properly rotated.
  • Monitor application access logs for anomalous administrative login events from unknown IP addresses, particularly those following a sequence of password resets or configuration changes.

Immediate actions

Audit Agnai deployments for use of default credentials defined in self-host.docker-compose.yml.

IT Operations 24h

Mitigations

Rotate administrative passwords and JWT signing secrets for all Agnai instances.

immediate IT Operations

CVE-2026-108753