Junglewise Threat Intelligence

CVE-2026-3873: Avantra hard-coded credentials in legacy built-in user account

CVE-2026-3873 · Severity: high · CVSS 7.2 · Published 2026-03-13

Technologies: Avantra. Vendors: Avantra.

Executive brief

Avantra, an operations platform for SAP monitoring and automation, contains a security flaw involving a legacy built-in user account with hard-coded credentials. An unauthorized person could use these credentials to access the system and perform actions that should be restricted by security rules. This could lead to unauthorized data access or configuration changes within the monitoring environment.

Technical details

A vulnerability classified as CWE-798 (Use of Hard-coded Credentials) exists in Avantra versions prior to 25.3.0. The flaw stems from a legacy built-in user account (rtm) that uses static credentials, which can be leveraged by an unauthenticated attacker over the network. Successful exploitation allows the attacker to bypass intended Access Control Lists (ACLs) and access restricted system functionality. The vulnerability is addressed in version 25.3.0.

Affected products

  • Avantra Avantra before 25.3.0

Timeline

  • 2026-03-13: disclosed
  • 2026-03-13: advisory

References