External risk intelligence

Agnaistic Agnai Hard-Coded Credentials Allow Unauthenticated Admin Access.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-108753

The vulnerability exists in a self-hosted application deployment configuration. Software designed for self-hosting in this context is commonly deployed as an internet-facing web service or API endpoint to facilitate remote access or external interaction, making public network exposure a standard and expected deployment pattern.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the Agnaistic agnai software, specifically within its self-hosted Docker Compose configuration. This issue involves hard-coded credentials that allow unauthenticated attackers to gain administrative access, impersonate users, and alter server settings. The primary concern is confirming if this software is in use and the extent of any potential exposure.

  • Hard-coded credentials allow unauthorized admin access.
  • Confirms software use and exposure to understand relevance.
  • Assess if our environment uses this self-hosted software.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can leverage the hard-coded credentials in the self-hosting configuration to gain administrative access. This allows them to impersonate users and alter server settings, potentially leading to a complete compromise of the system.

  • No authentication required for access.
  • Exploits hard-coded admin password and JWT secret.
  • Risk of unauthorized control and data manipulation.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to gain administrative access to the Agnaistic Agnai application when deployed with the default self-hosted Docker Compose configuration. This could lead to unauthorized modification of server settings, user data, and potentially compromise the integrity of the service.

  • Admin credentials and JWT secret.
  • Unauthenticated network access.
  • Server configuration changes.

Operational Fix

Recommended remediation, mitigation, and detection steps

For self-hosted deployments, application owners and platform teams are likely responsible for addressing this hard-coded credential vulnerability. The first practical step is to identify all instances of the affected technology, confirm their reachability and business criticality, and then locate the accountable owner to plan remediation based on risk.

  • Application owners should address the vulnerability.
  • Verify where the affected technology is deployed.
  • Plan remediation based on exposure and criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Agnaistic Agnai?

Agnaistic Agnai is a software platform designed to be self-hosted by users, typically to manage specific web-based services or APIs. By providing a containerized deployment method through Docker Compose, it allows individuals or organizations to run their own instances of the service. This self-hosting model puts the responsibility of configuration management, including security settings and access controls, directly on the person or team operating the software instance.

How does CVE-2026-108753 work?

This vulnerability is classified as Use of Hard-coded Credentials (CWE-798). It occurs because the default deployment file includes a preset administrative password and a static JSON Web Token (JWT) secret. Because these secrets are baked into the configuration rather than generated uniquely during installation, they remain the same across every instance. This flaw allows anyone to predict or discover these keys to bypass authentication and gain full control over the application.

Does this bug require a user to log in first?

No. The vulnerability does not require any prior authentication, meaning an attacker does not need a valid user account to interact with the system. The flaw is inherent in the configuration, so simply reaching the service over the network is enough to attempt unauthorized actions. It is important to note that this issue is specific to the default self-hosted configuration; custom deployments that do not use these hard-coded values may not be susceptible to this specific path.

Why is this CVE high priority for my network?

Halo Surface Signal indicates that Agnaistic Agnai is frequently deployed as an internet-facing web service to allow for remote access. Because this vulnerability grants administrative power without any authentication, any instance reachable from the public internet is at a significantly higher risk of unauthorized manipulation. If your instance is accessible from outside your local network, attackers can leverage this flaw to compromise the server regardless of your internal security policies.

What should I do if I run Agnaistic Agnai?

First, conduct an inventory to identify every instance of Agnai running within your infrastructure. Once identified, prioritize instances that are exposed to the public network or hold sensitive data. Your immediate goal is to verify your current deployment configuration against the known hard-coded credentials. Coordinate with your team to rotate these secrets and implement secure, unique credentials, while monitoring for any unauthorized changes to your server settings or user accounts.

References