Skip to content

Critical Embedded ActiveMQ Deserialization and Hard-Coded Credential Vulnerabilities in Armatura One Physical Access Control Platform

Security Advisory Brief

On October 1, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) published ICS advisory ICSA-26-274-01 disclosing five vulnerabilities in Armatura LLC Armatura One, a server-based platform used to manage physical access control systems. The flaws affect Armatura One versions prior to V4.7.2 and the USA release line prior to V4.6.1_USA. Successful exploitation could allow an attacker to gain unauthorized access to the platform database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system that governs doors, readers and credentials across a facility.

The most severe issue, CVE-2023-46604 with a CVSS v3.1 score of 9.8, stems from an embedded copy of Apache ActiveMQ whose OpenWire protocol listener is exposed on the network by default. This deserialization flaw lets an unauthenticated remote attacker execute code before any authentication check occurs. The remaining four vulnerabilities, CVE-2026-94591 and CVE-2026-94592 (each with a CVSS v3.1 score of 8.4), CVE-2026-94593 (CVSS 7.8) and CVE-2026-94594 (CVSS 4.0), are credential-handling weaknesses: a fixed encryption key and initialization vector shared by every installation, a vendor-defined database superuser password, and plain-text passwords written to backup and message-broker log files.

The risk is elevated because CVE-2023-46604, with a CVSS v3.1 score of 9.8, has been listed in the CISA Known Exploited Vulnerabilities (KEV) catalog since November 2, 2023, and has been used in the wild to deploy HelloKitty and TellYouThePass ransomware, Kinsing cryptomining malware and remote access trojans. Mature, publicly available exploit tooling for the ActiveMQ flaw means any reachable Armatura One server should be treated as a high-priority target. Because physical access control sits at the boundary between cyber and physical security, compromise of this platform could translate directly into unauthorized building entry, lockouts or loss of audit trails.

Threats and Vulnerabilities

CVE-2023-46604, with a CVSS v3.1 score of 9.8 and a CVSS v4.0 score of 9.3 (CVSS v4.0 scores in this advisory are calculated from the vectors CISA published), is a deserialization of untrusted data weakness (CWE-502) in the OpenWire marshaller of the Apache ActiveMQ broker embedded within Armatura One. Because the OpenWire listener is network-exposed by default, an unauthenticated attacker can send a crafted message that causes the broker to instantiate an arbitrary class, which in observed attacks loads a remote Spring XML configuration and launches operating system commands. Exploitation yields code execution with the highest level of privilege on the host. This vulnerability is listed in the CISA KEV catalog and has been actively exploited since at least October 2023 to deliver ransomware, cryptominers and remote access tooling. Any Armatura One server reachable from an untrusted network should be considered at immediate risk until upgraded.

CVE-2026-94591, with a CVSS v3.1 score of 8.4 and a CVSS v4.0 score of 8.6, is a use of hard-coded cryptographic key weakness (CWE-321). Armatura One stores database and message-broker credentials in an installation configuration file and, when that protection is enabled, encrypts them with AES-128-CBC; installations without it enabled hold the credentials unencrypted. Where encryption is used, the key and initialization vector are fixed values embedded in the software and identical across every installation. An attacker who obtains a copy of the installation package can recover these values and decrypt the stored credentials of any installation whose encrypted configuration file they separately acquire. This converts any configuration file leak, backup exposure or limited file-read foothold into full credential disclosure.

CVE-2026-94592, with a CVSS v3.1 score of 8.4 and a CVSS v4.0 score of 8.6, is a use of hard-coded credentials weakness (CWE-798). The Armatura One database initialization routine assigns a fixed, vendor-defined password to the database superuser account rather than generating a unique password for each installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on any deployment where it has not been changed. Superuser access exposes and permits modification of cardholder records, access levels and event history.

CVE-2026-94593, with a CVSS v3.1 score of 7.8 and a CVSS v4.0 score of 8.5, is an insertion of sensitive information into log file weakness (CWE-532). The backup and restore routine writes the full database connection command, including the superuser password, to a log file on the host in plain text. A low-privileged local user who can read that log can recover the credential and use it to access the database. This finding compounds CVE-2026-94592 by exposing the credential even where the default has been changed.

CVE-2026-94594, with a CVSS v3.1 score of 4.0 and a CVSS v4.0 score of 5.1, is a second insertion of sensitive information into log file weakness (CWE-532). The embedded message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or vendor support bundle that includes it, can obtain the logged credential. Organizations that routinely share support bundles with third parties should treat those bundles as containing live credentials.

Client Impact

Organizations running affected Armatura One deployments face a direct path from a single network-reachable service to full control of their physical access control environment. An attacker exploiting CVE-2023-46604 could add or alter cardholder credentials, unlock or lock doors, suppress alarms, or delete entry and exit history, while also using the compromised server as a foothold for ransomware deployment into the wider corporate or operational network. The credential weaknesses mean that even a partial compromise, such as theft of a backup or support bundle, can escalate into database-level control. Facilities such as utilities, manufacturing plants, data centers, healthcare campuses and government buildings that depend on access control for safety and security zoning are especially exposed to operational disruption and physical security incidents.

From a compliance perspective, physical access control systems are explicitly within scope of several regulatory frameworks. NERC CIP-006 requires electric utilities to protect physical access control systems governing Physical Security Perimeters, and an exploitable, internet-reachable or unpatched access control server may constitute a reportable deficiency. IEC 62443, TSA security directives and HIPAA physical safeguard requirements likewise expect organizations to manage known vulnerabilities and protect authentication data, and the presence of a KEV-listed vulnerability in an access control platform will draw scrutiny under federal binding operational directive timelines and cyber insurance reviews. Loss of reliable access logs may also undermine incident investigation and regulatory evidence obligations.

Mitigations

Organizations using Armatura One should take the following actions to reduce exposure to these vulnerabilities:

  1. Upgrade Armatura One to V4.7.2, or upgrade USA release line deployments to V4.6.1_USA, contacting Armatura LLC official technical support for guidance on obtaining and applying the upgrade.
  2. Restrict network access to the Armatura One server so that the embedded ActiveMQ OpenWire listener and database service are reachable only from required management hosts and controllers, remove any internet exposure, and place the system behind a firewall within a dedicated security zone.
  3. After upgrading, rotate the database superuser password, message-broker credentials and any other credentials stored in the installation configuration file, treating all previously stored values as compromised.
  4. Purge or securely restrict access to existing backup, restore and message-broker log files, and review any backups or support bundles previously shared with third parties for embedded plain-text credentials.
  5. Review Armatura One servers for indicators of prior compromise, including unexpected child processes spawned by the Java broker process, outbound connections to unfamiliar hosts, newly created accounts and unexplained changes to cardholder or access-level records, and require remote access to use a secure, monitored method such as a current VPN.

Applying these measures alongside CISA's ICS recommended practices for defense-in-depth will help reduce the likelihood that a compromise of the access control platform can be used to affect physical security or adjacent networks.

1898 & Co. Response

1898 & Co. supports organizations in assessing and securing the systems that bridge cyber and physical security, including physical access control platforms, building management systems and industrial control environments. Our team can help identify where Armatura One and similar platforms are deployed, determine whether vulnerable services are reachable from corporate, operational or internet-facing networks, and prioritize remediation based on operational impact.

Our consultants have supported utilities, manufacturers and critical infrastructure operators with vulnerability management, network segmentation design and NERC CIP and IEC 62443 compliance programs. We work alongside client security and facilities teams to plan upgrade and credential rotation activities that minimize disruption to site operations and physical security coverage.

1898 & Co. also delivers threat hunting and incident response services informed by current threat intelligence, including activity associated with exploitation of CVE-2023-46604. Clients seeking help reviewing Armatura One servers for signs of compromise, validating segmentation controls or developing a remediation roadmap can contact 1898 & Co. to discuss an engagement scoped to their environment.

Sources

  1. CISA ICS Advisory ICSA-26-274-01 — Armatura LLC Armatura One
  2. NVD Entry — CVE-2023-46604
  3. NVD Entry — CVE-2026-94591
  4. NVD Entry — CVE-2026-94592
  5. NVD Entry — CVE-2026-94593
  6. NVD Entry — CVE-2026-94594
  7. CISA Known Exploited Vulnerabilities Catalog
  8. MITRE CWE-502 — Deserialization of Untrusted Data
  9. MITRE CWE-321 — Use of Hard-coded Cryptographic Key
  10. MITRE CWE-798 — Use of Hard-coded Credentials
  11. MITRE CWE-532 — Insertion of Sensitive Information into Log File
  12. CISA — Industrial Control Systems Recommended Practices