CRITICAL
9.4 CVE-2026-108753 Published 11 Oct 2026
Agnaistic agnai Hard-Coded Credentials Vulnerability
Worried this affects your website?
Agnaistic agnai through 1.0.555 contains a hard-coded credentials vulnerability in self-host.docker-compose.yml.
The configuration sets a fixed admin password and a public JWT secret. Unauthenticated attackers can exploit this to:
- Log in as admin
- Sign their own JWT with admin: true to impersonate users
- Reset passwords
- Change server configuration
Reference: CVE-2026-108753 on NVD
← Back to Security News