{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/agnai--1.0.555/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:agnaistic:agnai:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.4,"id":"CVE-2026-108753"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["agnai (\u003c= 1.0.555)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Agnaistic"],"content_html":"\u003cp\u003eAgnaistic Agnai through version 1.0.555 is vulnerable to a hard-coded credentials flaw originating from the \u003ccode\u003eself-host.docker-compose.yml\u003c/code\u003e file. This configuration file ships with a fixed, publicly known administrative password and a static JWT signing secret. Because these secrets are predictable and embedded within the distribution's configuration template, any deployment using the default settings is susceptible to full administrative compromise by an unauthenticated attacker. This flaw allows malicious actors to authenticate as the administrator, generate forged JSON Web Tokens (JWTs) with administrative claims, perform unauthorized password resets, and gain complete control over the server configuration. The vulnerability is rated with a CVSS v3.1 base score of 9.4, highlighting the significant risk to deployments that do not explicitly rotate these secrets upon initial configuration.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to obtain full administrative control over the affected Agnai server. This grants the attacker the ability to manage all user accounts, modify server-wide settings, and access potentially sensitive data stored within the application instance. Organizations relying on default deployment configurations are at immediate risk of total service compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize remediation for all deployments of Agnai version 1.0.555 and earlier.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit all current Agnai deployments to determine if default credentials or the default JWT secret are in use.\u003c/li\u003e\n\u003cli\u003eUpdate to a version where these credentials are no longer hard-coded or manually rotate the admin password and JWT secret immediately.\u003c/li\u003e\n\u003cli\u003eRestrict network access to administrative interfaces to trusted IP addresses until secrets are properly rotated.\u003c/li\u003e\n\u003cli\u003eMonitor application access logs for anomalous administrative login events from unknown IP addresses, particularly those following a sequence of password resets or configuration changes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-11T14:01:07Z","date_published":"2026-10-11T14:01:07Z","id":"https://feed.craftedsignal.io/briefs/2026-10-agnai-hardcoded-creds/","summary":"Agnaistic Agnai versions 1.0.555 and earlier contain hard-coded administrative credentials and a static JWT secret, enabling unauthenticated account takeover and configuration manipulation.","title":"Hard-coded Credentials in Agnaistic Agnai","url":"https://feed.craftedsignal.io/briefs/2026-10-agnai-hardcoded-creds/"}],"language":"en","title":"CraftedSignal Threat Feed - Agnai (\u003c= 1.0.555)","version":"https://jsonfeed.org/version/1.1"}