{"id":"CVE-2026-54445","aliases":["GHSA-fgmc-2hqj-86v4","PYSEC-2026-3400"],"url":"https://o3.security/vulnerability/CVE-2026-54445","summary":"Vantage6: Set admin user and password from environment or configuration","details":"vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` and password `root`. This is not ideal because attackers know that almost all vantage6 servers have a user with username `root` that probably has admin rights, and the initial password is very weak and it is possible that administrators forget to reset it. Version 5.0.0 fixes the issue. As a workaround, it is possible to delete the `root` user after it has been used to create other users.","published":"2026-06-17T22:14:51.461Z","modified":"2026-08-12T03:51:14.707267738Z","cvss":null,"epss":{"score":0.00292,"percentile":0.21152,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"vantage6","fixedVersion":"5.0.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/vantage6/vantage6/blob/main/docs/release_notes.rst#500"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54445.json"},{"type":"ADVISORY","url":"https://github.com/vantage6/vantage6/security/advisories/GHSA-fgmc-2hqj-86v4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54445"},{"type":"REPORT","url":"https://github.com/vantage6/vantage6/issues/1932"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:14.707267738Z"}}