Agnaistic agnai through 1.0.555 contains a hard-coded credentials vulnerability in self-host.docker-compose.yml, which sets a fixed admin password and public JWT secret. Unauthenticated attackers can log in as admin or sign their own JWT with admin: true to impersonate users, reset passwords, and change server configuration.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Agnaistic agnai through 1.0.555 contains a hard-coded credentials vulnerability in self-host.docker-compose.yml, which sets a fixed admin password and public JWT secret. Unauthenticated attackers can log in as admin or sign their own JWT with admin: true to impersonate users, reset passwords, and change server configuration. | |
| Title | Agnaistic agnai through 1.0.555 Hard-Coded Credentials in self-host Docker Compose | |
| First Time appeared |
Agnai
Agnai agnai |
|
| Weaknesses | CWE-798 | |
| CPEs | cpe:2.3:a:agnai:agnai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Agnai
Agnai agnai |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T12:19:52.688Z
Reserved: 2026-10-11T01:54:17.948Z
Link: CVE-2026-108753
No data.
Status : Received
Published: 2026-10-11T13:17:20.237
Modified: 2026-10-11T13:17:20.237
Link: CVE-2026-108753
No data.
OpenCVE Enrichment
No data.
Weaknesses