Security1 publisher2 min readPublished
Armatura One's access-control software leaves a 2023 ActiveMQ flaw open to unauthenticated code execution
CISA warns Armatura One embeds an Apache ActiveMQ still open to the 2023 flaw CVE-2023-46604, letting any network attacker run code at top privilege. Upgrading to 4.7.2, or 4.6.1 for the US build, closes it alongside four CVEs assigned in 2026.
The Watch · Security desk

What happened
- Beyond running code, CISA says a successful attacker can reach Armatura One's database or seize control of the access-control system that governs a building's entry.
- The embedded ActiveMQ exposes its OpenWire listener on the network by default and deserializes attacker-supplied data before any authentication check runs.
- Armatura One is deployed worldwide in communications, critical manufacturing, energy and transportation environments, with the vendor headquartered in the United States.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Any host that can route to the OpenWire port can reach code execution at top privilege. Only network segmentation limits which hosts those are.
- constraint Upgrading patches the deserialization bug but does not change the shared AES key or the default superuser password, so sites that patch still have to rotate credentials an attacker may already hold.
- cost Each site has to go through Armatura technical support to obtain and apply the fix.
The deserialization runs before ActiveMQ checks who is talking to it. Its OpenWire marshaller unpacks an arbitrary object graph straight off the wire, and because the listener is exposed by default, a single crafted message to that port executes code as the host's highest-privileged account. [2][3][4]
Exploitation gives three outcomes, CISA says: access to the database, arbitrary code execution, or control of the physical access-control system itself. [5] Armatura One is a building access-control product, so that last outcome is control of entry. [1] It is deployed worldwide across communications, critical manufacturing, energy and transportation sites, and the vendor is based in the United States. [9]
The identifier dates the flaw to 2023. CISA filed the advisory under 2026 as ICSA-26-274-01, roughly three years after the CVE was assigned. [1][2]
The advisory assigns four more CVE identifiers, all dated 2026 [1], and describes two further weaknesses, both secrets built into the software. Armatura One encrypts stored database and broker credentials with AES-128-CBC, but the key and initialization vector are fixed values embedded in the software and identical on every install, so anyone holding the installer can recover them and decrypt the credentials from any deployment's config file they get hold of. [10] The database superuser is created with a fixed, vendor-defined password that is not unique per site. Anyone with server access and that value can log in as superuser where it was never changed. [11] Both need more access than the ActiveMQ flaw does.
The fix is Armatura One 4.7.2 on the main line and 4.6.1_USA on the US build; sites on 4.7.1 or earlier, and 4.3.1_USA or earlier, are told to upgrade. [6][7][8] The update comes through Armatura technical support, which the vendor says to contact to obtain and apply it. [12]
What to watch
- Whether CISA or researchers report in-the-wild exploitation of the embedded ActiveMQ instance in Armatura One deployments.
- Whether a future Armatura build rotates the shared AES key and the per-site superuser password rather than only patching the deserialization flaw.
- How the four 2026 CVE identifiers are scored and which weaknesses each maps to.