{"vuid":"VU#243636","idnumber":"243636","name":"VPS.org one-click deployment templates contain multiple vulnerabilities","keywords":null,"overview":"### Overview\r\nVPS.org's one-click deployment templates provision services with default passwords and predefined network bindings instead of generating randomized secrets or applying per-deployment hardening measures.\r\n\r\n### Description\r\nVPS.org is a cloud and virtual private server hosting provider that offers a library of templates for quickly provisioning common applications and services. Multiple vulnerabilities exist in the one-click deployment templates feature. These vulnerabilities stem from the same root cause: content is directly instantiated from static templates, using default passwords and static secrets with no deployment-specific randomization or interface-binding hardening at provisioning time. \r\n\r\n**CVE-2026-16503** The `Supabase` template provides an instance of PostgreSQL that is bound to all network interfaces `(0.0.0.0:5432)` and uses the hard-coded database password `postgres`. Because Docker manages its own iptables rules, this exposure can bypass standard host UFW firewall configurations. If the the instance is exposed to the internet, a remote attacker could connect to the host's published `TCP port 5432` and authenticate as the `postgres` superuser account using the default `postgres` password.\r\n\r\n**CVE-2026-16504** The `Zulip` template ships with a hard-coded application key `secret_key: changeme`, a default database password `zulip`, and the setting `DISABLE_HTTPS=True`. An attacker can use this public secret key to forge or validate signed session material, enabling session forgery and authentication bypass against the instance. If unchanged, the default database password `zulip` can be used to authenticate to the database. Furthermore, the `DISABLE_HTTPS=True` configuration causes all traffic to be sent over unencrypted HTTP by default, exposing credentials and session data to potential interception in certain deployments.\r\n\r\n### Impact\r\nCVE-2026-16503 (Supabase template): PostgreSQL superuser access from the internet enables the following:\r\n* read and exfiltrate data\r\n* insert/modify/delete data\r\n* alter the database schema, roles, and privileges\r\n* establish persistence via database objects \r\n* denial of service through destructive statements (dropping tables/databases)\r\n\r\nCVE-2026-16504 (Zulip template): Authentication bypass and session forgery allows the following: \r\n* account and instance takeover\r\n* interception of credentials and session tokens over unencrypted transport\r\n\r\nThis constitutes a *Technical Impact = Total* under the [SSVC](https://certcc.github.io/SSVC/reference/decision_points/technical_impact/) framework, meaning:\r\n> The vulnerability gives the adversary total control over the behavior of the software or total disclosure of all information on the affected system.\r\n\r\n### Solution\r\nUnfortunately, VPS.org could not be reached to coordinate these vulnerabilities, and a patch is not yet available. Users of VPS.org one-click deployment templates are advised to change any default passwords and secret keys before deploying to a production environment. Firewall rules and network segmentation should be implemented to restrict internet access to back-end systems such as databases and other sensitive resources. Finally, where applicable, HTTPS should be enabled to protect credentials and session data in transit. \r\n\r\n### Acknowledgements\r\nThank you to Simon Gajdosik for reporting these vulnerabilities. This document was written by Bob Kemerer.","clean_desc":null,"impact":null,"resolution":null,"workarounds":null,"sysaffected":null,"thanks":null,"author":null,"public":["https://www.vps.org/"],"cveids":["CVE-2026-16503","CVE-2026-16504"],"certadvisory":null,"uscerttechnicalalert":null,"datecreated":"2026-07-31T15:15:50.468321Z","publicdate":"2026-07-31T15:15:50.332087Z","datefirstpublished":"2026-07-31T15:15:50.485667Z","dateupdated":"2026-07-31T15:20:13.991807Z","revision":2,"vrda_d1_directreport":null,"vrda_d1_population":null,"vrda_d1_impact":null,"cam_widelyknown":null,"cam_exploitation":null,"cam_internetinfrastructure":null,"cam_population":null,"cam_impact":null,"cam_easeofexploitation":null,"cam_attackeraccessrequired":null,"cam_scorecurrent":null,"cam_scorecurrentwidelyknown":null,"cam_scorecurrentwidelyknownexploited":null,"ipprotocol":null,"cvss_accessvector":null,"cvss_accesscomplexity":null,"cvss_authentication":null,"cvss_confidentialityimpact":null,"cvss_integrityimpact":null,"cvss_availabilityimpact":null,"cvss_exploitablity":null,"cvss_remediationlevel":null,"cvss_reportconfidence":null,"cvss_collateraldamagepotential":null,"cvss_targetdistribution":null,"cvss_securityrequirementscr":null,"cvss_securityrequirementsir":null,"cvss_securityrequirementsar":null,"cvss_basescore":null,"cvss_basevector":null,"cvss_temporalscore":null,"cvss_environmentalscore":null,"cvss_environmentalvector":null,"metric":null,"vulnote":230}