Executive brief
vantage6, an open-source platform for privacy-preserving data analysis, contains a security weakness where new installations are configured with a default administrative account. Because this account uses a well-known username and password, unauthorized individuals can easily gain full control over the server if the administrator does not manually change these credentials. This could lead to the exposure of sensitive research data or unauthorized modification of the analysis infrastructure.
Technical details
vantage6 versions prior to 5.0.0 implement a default administrative user with the credentials 'root:root'. This vulnerability is classified as a Use of Default Password (CWE-1393). An attacker with network access to the vantage6 server can use these well-known credentials to authenticate as a superuser, gaining full administrative control over the infrastructure and hosted data. The issue is exacerbated by the fact that administrators may neglect to rotate these credentials post-deployment. The vulnerability is resolved in version 5.0.0; a workaround involves manually deleting the root user after creating alternative administrative accounts.
Affected products
- vantage6 vantage6 < 5.0.0
Timeline
- 2025-05-10: other: Issue tracked for major version 5.0 implementation
- 2026-06-05: advisory: GitHub Security Advisory published
- 2026-06-17: disclosed: CVE published to NVD
- 2026-06-17: patched: Version 5.0.0 released fixing the issue