VPS.org One-Click Templates Ship Hardcoded Passwords, Leaving Servers Open to Takeover
Security researchers disclosed two high-severity vulnerabilities, CVE-2026-16503 and CVE-2026-16504, in VPS.org one-click deployment templates for Supabase and Zulip, published by JVN on August 3, 2026. The Supabase template exposes PostgreSQL on all network interfaces using the hardcoded superuser password 'postgres', potentially bypassing host firewall rules via Docker NAT and allowing unauthenticated remote access. The Zulip template deploys with a known secret key, a default database password, and HTTPS disabled, enabling attackers to forge session tokens and take over accounts. Both flaws stem from templates failing to generate unique, deployment-specific secrets, meaning any internet-exposed instance is immediately vulnerable after setup. No patches are available and no vendor contact has been established, so operators are advised to manually rotate all credentials, restrict database binding, and enforce HTTPS before or instead of using these templates.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in