CRITICAL 9.4 CVE-2026-108753 Published 11 Oct 2026

Agnaistic agnai Hard-Coded Credentials Vulnerability

Worried this affects your website?

Agnaistic agnai through 1.0.555 contains a hard-coded credentials vulnerability in self-host.docker-compose.yml.

The configuration sets a fixed admin password and a public JWT secret. Unauthenticated attackers can exploit this to:

  • Log in as admin
  • Sign their own JWT with admin: true to impersonate users
  • Reset passwords
  • Change server configuration

Reference: CVE-2026-108753 on NVD

← Back to Security News