PatchSiren

vantage6 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM vantage6 CVE published 2026-06-17

CVE-2026-54533

CVE-2026-54533 is a security vulnerability in Vantage6, an open-source infrastructure for privacy-preserving analysis. Prior to version 5.0.0, malicious algorithms can potentially access other algorithms' input and output files. This issue allows unauthorized access to sensitive data. Version 5.0.0 fixes the issue. As a workaround, verify and restrict the algorithm containers that are allowed to run on th [truncated]

MEDIUM vantage6 CVE published 2026-06-17

CVE-2026-54445

CVE-2026-54445 is a medium-severity vulnerability in vantage6, an open-source infrastructure for privacy-preserving analysis. The issue arises from versions prior to 5.0.0 providing an initial user with a default username of 'root' and password 'root'. This is a security risk as attackers are likely to know that many vantage6 servers have a 'root' user with admin rights and the initial password is weak. A [truncated]

MEDIUM vantage6 CVE published 2026-06-17

CVE-2024-27928

CVE-2024-27928 is a medium-severity vulnerability in vantage6, an open-source infrastructure for privacy-preserving analysis. If an attacker gains access to a user's email account, they can reset the password and 2FA token via email, effectively reducing 2FA to 1FA. This issue is not likely to cause significant problems due to the widespread use of 2FA in email providers. However, users of vantage6, espec [truncated]

LOW vantage6 CVE published 2026-06-17

CVE-2024-24769

CVE-2024-24769 is a low-severity vulnerability in vantage6, an open-source infrastructure for privacy preserving analysis. The issue allows users to reset their MFA token via API routes that send an email, but the number of emails sent is not limited, potentially flooding a user's mailbox and impacting the SMTP server. However, resetting the MFA token requires a correct password, limiting the impact. The [truncated]