# Armatura One access-control system has critical flaws

Published: 2026-10-01 · Severity: high · Sectors: telecommunications, manufacturing, energy, transportation
Canonical: https://vorant.io/reports/4681de86-59b5-55c0-8542-e400b276f34c/armatura-one-access-control-system-has-critical-flaws

> Armatura One physical access-control software bundles a vulnerable Apache ActiveMQ and hard-coded credentials, risking full system compromise; patch to 4.7.2/4.6.1.

CISA has published an ICS advisory for Armatura LLC's Armatura One physical access-control platform, detailing five vulnerabilities affecting versions prior to 4.7.2 (and 4.6.1 for the USA release line). The most severe, CVE-2023-46604, stems from an embedded, network-exposed Apache ActiveMQ instance vulnerable to a well-known OpenWire deserialization flaw that allows unauthenticated remote code execution with the highest host privileges. This CVE is already listed in CISA's KEV catalog and has been used in ransomware campaigns against other ActiveMQ deployments, though CISA states it is not aware of exploitation specifically targeting Armatura One.

The remaining four vulnerabilities compound the risk: a hard-coded AES-128-CBC key/IV used across all installations (CVE-2026-94591) lets an attacker with the installer decrypt stored database/broker credentials; a fixed, vendor-defined database superuser password set at install time (CVE-2026-94592) permits local authentication if unchanged; plaintext logging of database superuser credentials during backup/restore (CVE-2026-94593); and plaintext logging of message-broker client credentials during normal operation (CVE-2026-94594). Together these could let an attacker move from network access to full database and physical access-control system compromise.

Affected deployments span Communications, Critical Manufacturing, Energy, and Transportation Systems sectors worldwide, with the vendor headquartered in the US. Armatura has released fixed versions 4.7.2 (general) and 4.6.1_USA (USA line); defenders should upgrade immediately, rotate any potentially exposed database/broker credentials, isolate control system networks from the internet and business networks, and use VPNs for remote access. The vulnerabilities were reported to CISA by Andrew Capobianco of RewCon.co.

## Mentioned in this report

- Vulnerabilities: CVE-2023-46604 (KEV), CVE-2026-94591, CVE-2026-94592, CVE-2026-94593, CVE-2026-94594

## Detection guidance (public sample)

### ActiveMQ Java Process Spawning Shell or Download Utility (Windows)

ATT&CK: T1190

Detects a Java process running Apache ActiveMQ spawning a shell, scripting host or download utility, consistent with CVE-2023-46604 OpenWire deserialization RCE on embedded brokers such as Armatura One. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: ActiveMQ Java Process Spawning Shell or Download Utility (Windows)
id: 408ca016-62c2-508d-9478-9d5b9ff0e73e
status: experimental
description: Detects a Java process hosting Apache ActiveMQ spawning cmd, PowerShell,
  script hosts or LOLBin download utilities. This is the typical post-exploitation
  pattern of CVE-2023-46604 (OpenWire deserialization RCE) against embedded ActiveMQ
  brokers such as the one in Armatura One. Matches on the parent/child relation, not
  on payload names.
tags:
- attack.initial-access
- attack.t1190
- attack.execution
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
    - \java.exe
    - \javaw.exe
    ParentCommandLine|contains: activemq
  selection_child:
    Image|endswith:
    - \cmd.exe
    - \powershell.exe
    - \pwsh.exe
    - \wscript.exe
    - \cscript.exe
    - \mshta.exe
    - \certutil.exe
    - \bitsadmin.exe
    - \curl.exe
    - \rundll32.exe
    - \regsvr32.exe
    - \msiexec.exe
  condition: selection_parent and selection_child
falsepositives:
- Administrator-written ActiveMQ wrapper or maintenance scripts launched via cmd from
  the broker service
- Service installers or upgrade routines that invoke cmd.exe from the ActiveMQ Java
  process
level: high
author: Vorant
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01
```

### ActiveMQ Java Process Spawning Shell or Download Utility (Linux)

ATT&CK: T1190

Detects a Java process running Apache ActiveMQ spawning a shell, downloader or netcat on Linux, consistent with CVE-2023-46604 exploitation. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: ActiveMQ Java Process Spawning Shell or Download Utility (Linux)
id: a65e1291-8f6f-531c-b513-d3173cb5dc02
status: experimental
description: Detects the Java process hosting Apache ActiveMQ spawning a shell, curl,
  wget, netcat or scripting interpreter on Linux. This is the typical post-exploitation
  pattern of CVE-2023-46604 (OpenWire deserialization RCE) against exposed brokers.
tags:
- attack.initial-access
- attack.t1190
- attack.execution
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith: /java
    ParentCommandLine|contains: activemq
  selection_child:
    Image|endswith:
    - /sh
    - /bash
    - /dash
    - /curl
    - /wget
    - /nc
    - /ncat
    - /python
    - /python3
    - /perl
  condition: selection_parent and selection_child
falsepositives:
- ActiveMQ startup or wrapper scripts that call sh or bash from the broker JVM
- Custom broker health-check scripts invoked by the Java process
level: high
author: Vorant
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01
```

### Recursive Search of Log Files for Plaintext Passwords

ATT&CK: T1552.001

Detects findstr or Select-String being used to search log files for password strings, which would expose the plaintext credentials logged by the Armatura One backup/restore and broker flaws. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Recursive Search of Log Files for Plaintext Passwords
id: 4569ad63-ab25-53be-8a7f-69e689d96cc6
status: experimental
description: Detects findstr or Select-String being used to search log files for password
  strings. Applications that log database superuser or message-broker credentials
  in plaintext (as described for Armatura One CVE-2026-94593 and CVE-2026-94594) expose
  them to this kind of credential harvesting. Tune by excluding known admin troubleshooting
  accounts.
tags:
- attack.credential-access
- attack.t1552.001
logsource:
  category: process_creation
  product: windows
detection:
  selection_findstr:
    Image|endswith: \findstr.exe
    CommandLine|contains|all:
    - /s
    - password
    - .log
  selection_pwsh:
    Image|endswith:
    - \powershell.exe
    - \pwsh.exe
    CommandLine|contains|all:
    - Select-String
    - password
    - .log
  condition: 1 of selection_*
falsepositives:
- Administrators troubleshooting application logs for authentication errors
- Security audit or secret-scanning scripts run by IT staff
level: medium
author: Vorant
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4681de86-59b5-55c0-8542-e400b276f34c/armatura-one-access-control-system-has-critical-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
