PatchSiren

vantage6 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM vantage6 CVE published 2026-06-17

CVE-2026-54445

CVE-2026-54445 is a medium-severity vulnerability in vantage6, an open-source infrastructure for privacy-preserving analysis. The issue arises from versions prior to 5.0.0 providing an initial user with a default username of 'root' and password 'root'. This is a security risk as attackers are likely to know that many vantage6 servers have a 'root' user with admin rights and the initial password is weak. A [truncated]