Junglewise Threat Intelligence

CVE-2026-85649: Chew Kean Ho Actualizer fail-open password validation

CVE-2026-85649 · Severity: high · CVSS 7.9 · Published 2026-09-04

Executive brief

Actualizer is a system image building tool that uses shell scripts to configure new system installations. The tool fails to validate password hash generation for the root and alpha user accounts; if the underlying mkpasswd command fails (due to missing yescrypt support), the installer accepts empty password fields instead of aborting. This can result in built images where these privileged accounts have no password protection, allowing passwordless authentication.

Technical details

The vulnerability is a fail-open authentication bypass (CWE-636) combined with unchecked return value (CWE-252) in Shell/debian-minbase-install.sh. The installer invokes mkpasswd to generate yescrypt password hashes for root and alpha accounts but does not validate the command's return value or check whether the resulting hash variable is empty. If mkpasswd fails (e.g., on systems without yescrypt support or with incompatible implementations), the password hash variables remain empty and are written to the system's password files unchecked. An attacker with local access or knowledge of the build process can exploit this by building an image on a system lacking yescrypt support, resulting in privileged accounts with empty password fields. The vulnerability was fixed in v1.2.1 (released 2026-08-27) by adding empty password hash validation checks.

Affected products

  • Chew Kean Ho Actualizer v1.2.0 and earlier

Timeline

  • 2026-08-26: disclosed: Vulnerability reported
  • 2026-08-27: patched: Fix released as v1.2.1
  • 2026-09-04: advisory: Public disclosure via NVD

References