← Back to feed
Vulnerabilities & PatchesEmerging1 sourceJul 31, 2026 · 15:15via CERT/CC Vulnerability Notes

VU#243636: VPS.org one-click deployment templates contain multiple vulnerabilities

Brief

Overview

VPS.org's one-click deployment templates provision services with default passwords and predefined network bindings instead of generating randomized secrets or applying per-deployment hardening measures.

Description

VPS. org is a cloud and virtual private server hosting provider that offers a library of templates for quickly provisioning common applications and services. Multiple vulnerabilities exist in the one-click deployment templates feature.

These vulnerabilities stem from the same root cause: content is directly instantiated from static templates, using default passwords and static secrets with no deployment-specific randomization or interface-binding hardening at provisioning time.

CVE-2026-16503 The Supabase template provides an instance of PostgreSQL that is bound to all network interfaces (0.

  • 0. 0:5432) and uses the hard-coded database password postgres .
Read more on CERT/CC Vulnerability Notes