Overview
CVE ID: CVE-2026-8672
Severity: Medium
CVSS Score: 5.1
Affected Product(s): Avantra
Fixed Version(s): 25.3.x
Description
Use of default password vulnerability in Avantra on Linux, Windows allows Try Common or Default Usernames and Passwords. This issue affects Avantra: before 25.3.0
Impact
Vector: Local
Confidentiality: High
Integrity: Low
Availability: None
Exploitation Status: No known exploits in the wild
Solution & Mitigation
Upgrading to Avantra 25.3.x or later does not change the database credentials by itself. The upgrade adds the ability to configure a custom Agent database user and password, but this configuration step is not applied automatically. Both steps below are required to remediate this vulnerability.
Step 1 – Upgrade: Upgrade to Avantra 25.3.x or later.
-
Step 2 – Configure a custom Agent database user and password: This must be done on every host running an Avantra Agent.
Set the environment variables
AVA_DB_USRandAVA_DB_PWDfor the operating system user or service account that runs the Avantra Agent.Restart the Agent. On the first restart with the new credentials, the Agent cannot open its existing local database. It writes an error to the Agent log, then automatically removes and recreates the database using the new credentials. This is expected. The database only holds buffered monitoring data and detection results — it never stores credentials for your SAP or IT systems.
Detailed instructions:
References
Contact & Credits
Reported by: Special thanks to Vicxer Inc. for identifying this vulnerability and working with us to strengthen our platform’s security.
Support: support@avantra.com
We, at Avantra, take the security of our software and our customers very seriously and it is our top priority. We will keep you up to date as more information becomes available and encourage customers to subscribe to the security section of our forum to get proactive updates as we post them.