Back to Intelligence

CVE-2026-108753: Agnaistic Agnai Hard-Coded Credentials in Docker Compose — Detection and Remediation Guide

SA
Security Arsenal Team
October 11, 2026
9 min read

The NVD has published CVE-2026-108753, a CVSS 9.4 (Critical) vulnerability affecting Agnaistic Agnai through version 1.0.555 — a popular open-source, self-hostable AI chat/front-end platform commonly deployed via Docker. The flaw is embarrassingly simple and catastrophically effective: the project's self-host.docker-compose.yml ships with a hard-coded admin password and a publicly known JWT secret.

Because the JWT signing secret is public and identical across every default deployment, an unauthenticated, network-adjacent attacker has two independent paths to full compromise:

  1. Log in directly as the admin user using the fixed credential.
  2. Forge a JWT offline with admin: true claims, signing it with the known secret — no login required.

From there, the attacker can impersonate arbitrary users, reset passwords, and modify server configuration. Any organization running Agnai self-hosted with the default compose file — especially anything exposed to the internet — should treat this as an incident-in-waiting. If your instance is reachable and running ≤ 1.0.555 with unchanged secrets, assume compromise and move to response mode, not just patching.

Technical Analysis

Affected Products and Versions

AttributeDetail
ProductAgnaistic Agnai (self-hosted)
Affected versionsThrough 1.0.555
Componentself-host.docker-compose.yml
CWE classCWE-798 (Use of Hard-coded Credentials) / CWE-347 (Improper Verification of Cryptographic Signature, by consequence)
CVSS9.4 — Critical, network-exploitable, no authentication required
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-108753

Root Cause

The vulnerable compose file pre-seeds two security-critical values with static, publicly visible defaults:

  • A fixed administrator password applied to the seeded admin account on first boot.
  • A fixed JWT secret used to sign and validate session tokens.

Both values live in a file that is committed to the public repository and copied verbatim by users following the official self-hosting documentation. Anyone who has ever read the repo knows the keys to every unmodified deployment on the internet.

Attack Chain (Defender's View)

  1. Discovery — Attacker scans for exposed Agnai instances (the web UI and /api endpoints are fingerprintable; Shodan/Censys exposure of self-hosted AI front-ends is well documented in 2025–2026).
  2. Path A — Direct login: POST to the authentication endpoint with the known admin username and the hard-coded password. A valid session JWT is returned.
  3. Path B — JWT forgery: Attacker mints a token locally with a payload containing admin: true (or any target user's ID) and signs it with the public secret using any JWT library. The server validates the signature — it has no way to distinguish forged tokens from legitimate ones.
  4. Post-exploitation — With admin-level API access: enumerate users, impersonate any account, reset passwords (locking out legitimate users or taking over their sessions), and alter server configuration — which, depending on deployment, can influence upstream model endpoints, API keys stored in config, and connected integrations.

The CVSS 9.4 score reflects exactly this: remote, unauthenticated, trivially exploitable, with high impact to confidentiality and integrity.

Exploitation Status

At time of writing, CVE-2026-108753 is newly published and we have no confirmed CISA KEV listing. However, the barrier to exploitation is effectively zero — no exploit code is needed beyond curl and a JWT library, and the secrets are in the public git history. Treat public exposure of this bug as equivalent to PoC availability. Scanning for default-credential targets of this class routinely begins within hours of disclosure.

Detection & Response

This is a technical threat. The detection strategy focuses on three observable behaviors: (1) admin authentication events from unexpected sources, (2) JWT replay/forgery indicators in web access logs, and (3) the presence of the vulnerable compose file with unchanged secrets.

SIGMA Rules

YAML
---
title: Agnai Admin Authentication from External or Anomalous Source
tatus_field_note: none
id: 3f8a2c71-9b4d-4e5a-a1c2-6d7e8f9a0b1c
status: experimental
description: Detects successful admin login attempts against a self-hosted Agnai instance, a primary exploitation vector of CVE-2026-108753 where a hard-coded admin password is used.
references:
  - https://nvd.nist.gov/vuln/detail/CVE-2026-108753
author: Security Arsenal
date: 2026/01/15
tags:
  - attack.initial_access
  - attack.t1078
  - attack.t1078.004
logsource:
  category: webserver
  product: linux
detection:
  selection:
    cs-method: 'POST'
    cs-uri|contains:
      - '/auth/login'
      - '/api/auth'
      - '/login'
    sc-status:
      - 200
      - 201
  filter_internal:
    c-ip|startswith:
      - '10.'
      - '172.16.'
      - '192.168.'
  condition: selection and not filter_internal
falsepositives:
  - Legitimate admin logins via VPN or reverse proxy (tune filter_internal to your egress/proxy IPs)
level: high
---
title: Agnai Administrative Configuration or Password Reset Activity
tatus_field_note: none
id: 8c4d1e62-2a7f-4b39-9d5c-1e6f7a8b9c0d
status: experimental
description: Detects password reset, user modification, and server configuration change requests against Agnai API endpoints, consistent with post-compromise activity following CVE-2026-108753 exploitation.
references:
  - https://nvd.nist.gov/vuln/detail/CVE-2026-108753
author: Security Arsenal
date: 2026/01/15
tags:
  - attack.persistence
  - attack.t1098
  - attack.t1078
logsource:
  category: webserver
  product: linux
detection:
  selection:
    cs-method:
      - 'POST'
      - 'PUT'
      - 'PATCH'
      - 'DELETE'
    cs-uri|contains:
      - '/admin'
      - '/config'
      - '/settings'
      - '/password'
      - '/user'
  condition: selection
falsepositives:
  - Normal administrative use — baseline admin source IPs and alert on deviations
level: medium
---
title: Deployment of Vulnerable Agnai Self-Host Compose File
tatus_field_note: none
id: 5e2b7a44-6c1d-48e3-b2f9-0a4c5d6e7f8a
status: experimental
description: Detects docker compose invocations referencing self-host.docker-compose.yml, identifying potentially vulnerable Agnai deployments that may carry the hard-coded credentials from CVE-2026-108753.
references:
  - https://nvd.nist.gov/vuln/detail/CVE-2026-108753
author: Security Arsenal
date: 2026/01/15
tags:
  - attack.execution
  - attack.t1059
logsource:
  category: process_creation
  product: linux
detection:
  selection:
    CommandLine|contains:
      - 'self-host.docker-compose.yml'
      - 'docker-compose up'
      - 'compose up'
  condition: selection
falsepositives:
  - Legitimate Agnai administration — use as an inventory/hunting rule to enumerate exposure
level: low

KQL — Microsoft Sentinel / Defender

Hunt external admin authentication and administrative API activity against Agnai hosts. This assumes web/reverse-proxy logs (nginx, Traefik, Caddy) reach Sentinel via Syslog/CEF, or that IIS/front-end logs are ingested as W3CIISLog.

KQL — Microsoft Sentinel / Defender
let AgnaiHosts = dynamic(["agnai", "agnai-web", "agnai-server"]); // tune to your hostnames/IPs
union isfuzzy=true
    (CommonSecurityLog
    | where RequestMethod == "POST"
    | where RequestURL has_any ("/auth/login", "/api/auth", "/login")
    | where ApplicationProtocol =~ "http" or ApplicationProtocol =~ "https"
    | where not (ipv4_is_private(SourceIP))
    | project TimeGenerated, SourceIP, DestinationHostName, RequestURL, RequestMethod, DeviceAction, SourceUserAgent),
    (W3CIISLog
    | where csMethod == "POST"
    | where csUriStem has_any ("/auth/login", "/api/auth", "/login")
    | where not (ipv4_is_private(cIP))
    | project TimeGenerated, cIP, sSiteName, csUriStem, csMethod, scStatus, csUserAgent)
| summarize LoginAttempts = count(), DistinctSources = dcount(SourceIP) by bin(TimeGenerated, 1h), RequestURL
| order by TimeGenerated desc;
// Second hunt: administrative mutations (password resets, config changes)
CommonSecurityLog
| where RequestMethod in ("POST", "PUT", "PATCH", "DELETE")
| where RequestURL has_any ("/admin", "/config", "/settings", "/password")
| summarize Actions = count(), Endpoints = make_set(RequestURL) by SourceIP, bin(TimeGenerated, 15m)
| where Actions > 3  // burst threshold — tune to baseline
| order by TimeGenerated desc

Velociraptor VQL

Use this hunt artifact to enumerate Agnai deployments and, critically, to read the compose file and check whether the default hard-coded secrets are still in place — the single most important exposure check for this CVE.

VQL — Velociraptor
-- CVE-2026-108753: Find Agnai self-host compose files and flag unchanged hard-coded secrets
LET compose_files = SELECT FullPath, Size, Mtime
FROM glob(globs=['/**/self-host.docker-compose.yml', '/**/docker-compose*.yml'], root='/')
WHERE FullPath =~ 'agnai'

SELECT FullPath,
       Mtime AS ComposeModified,
       parse_string_with_regex(
         string=read_file(filename=FullPath, length=100000),
         regex='(?i)(jwt[_-]?secret|admin[_-]?password|JWT_SECRET|ADMIN_PASSWORD)[^\n]*'
       ) AS SecretLines
FROM compose_files

Review the SecretLines output on every hit. Any instance still containing the upstream default values is exploitable from the network today.

Remediation / Verification Script

Run on any Docker host suspected of running Agnai. The script locates the deployment, reports whether default secrets remain, and forces regeneration.

Bash / Shell
#!/usr/bin/env bash
# CVE-2026-108753 — Agnai hard-coded credential check and rotation
set -euo pipefail

echo "[*] Locating Agnai containers and compose files..."
docker ps -a --format '{{.Names}}\t{{.Image}}' | grep -i agnai || echo "  No running Agnai containers found."
COMPOSE_FILES=$(find /opt /srv /home /root -maxdepth 6 -name '*docker-compose*.yml' 2>/dev/null | xargs grep -il 'agnai' 2>/dev/null || true)

if [ -z "$COMPOSE_FILES" ]; then
  echo "[-] No Agnai compose files found. Verify manually if deployed elsewhere."
  exit 0
fi

for f in $COMPOSE_FILES; do
  echo ""
  echo "[*] Inspecting: $f"
  # Flag static JWT secret / admin password values in the compose file
  grep -nEi 'jwt|secret|admin|password' "$f" || echo "  No credential keys found inline."
done

echo ""
echo "[!] ACTION REQUIRED:"
echo "  1. Pull the patched release:  cd \$(dirname \"$COMPOSE_FILES\" | head -1) && docker compose pull && docker compose up -d"
echo "  2. Rotate the JWT secret to a unique random value:"
echo "       NEW_SECRET=\$(openssl rand -hex 48)"
echo "     Set JWT_SECRET=\$NEW_SECRET in your .env / compose file."
echo "  3. Reset the admin password via the UI or CLI after upgrade."
echo "  4. NOTE: Rotating JWT_SECRET invalidates all existing sessions —"
echo "     this is intentional and kills any forged attacker tokens."
echo "  5. Audit user accounts for unauthorized admin-role grants before re-enabling access."

Remediation

  1. Upgrade immediately. Update Agnai to the latest release beyond 1.0.555. Pull current images and redeploy: docker compose pull && docker compose up -d. Confirm the running image digest matches the patched release from the upstream project.
  2. Rotate both secrets — this is non-negotiable. Generate a unique, high-entropy JWT secret (openssl rand -hex 48) and a unique admin password via environment variables (.env), never committed to the compose file. Rotating the JWT secret instantly invalidates every forged token in an attacker's hands — until you do this, patching alone does not evict an adversary.
  3. Audit for compromise before returning to service. Review Agnai user accounts for unexpected admin-role grants, password changes you did not initiate, and configuration modifications (upstream endpoints, stored API keys, integrations). Check web/reverse-proxy logs for admin logins from non-administrative source IPs.
  4. Restrict network exposure. Self-hosted AI front-ends should not be internet-facing without authentication-aware fronting. Place Agnai behind a VPN, SSO-aware reverse proxy (e.g., Authentik/Authelia/oauth2-proxy), or IP allowlist. If it must be public, enforce TLS and strong perimeter auth.
  5. Adopt secure-by-default deployment hygiene. Never run vendor compose files verbatim in production. Diff any upstream docker-compose.yml against your deployed copy on every update — credential defaults change silently.
  6. Monitor authoritative sources. Track the NVD entry (https://nvd.nist.gov/vuln/detail/CVE-2026-108753), the Agnaistic GitHub security advisories, and CISA KEV for updates on exploitation status. Given the triviality of exploitation, a KEV addition or mass-scanning reports are plausible; reassess urgency if either materializes.

If your Agnai instance was internet-exposed with default secrets for any period of time, treat it as compromised: rotate not only the Agnai admin credential and JWT secret, but any API keys or downstream credentials stored in its configuration.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.