CVE-2026-90456
Last modified
CVE-2026-90456 is a critical-severity vulnerability rated 9.2/10 on the CVSS scale. An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value..
Description
An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| CISA | Malcolm | < v26.06.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-90456?
How severe is CVE-2026-90456?
How do I fix CVE-2026-90456?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-90450The application's role-authorization lookup defaults to gran…5.3
- CVE-2026-90451An example environment-configuration file ships with a fixed…8.2
- CVE-2026-90452Requests from the reverse proxy to the identity-provider ser…6
- CVE-2026-90453A file-upload handler redirects the authenticated client's b…5.1
- CVE-2026-90454A deployment mode intended to expose only read access to a b…5.3
- CVE-2026-90455A prior update that raised a bundled HTTP client library to …6.3
- CVE-2026-90457The administrative password is hashed using a comparatively …6.9
- CVE-2026-9046A potential insecure permissions vulnerability was reported …7.3
- CVE-2026-90460An issue was discovered in OpenStack Keystone before 29.0.3.…7.6
- CVE-2026-90461OpenStack Ironic through 38.0.0 may send a username and pass…6.3
- CVE-2026-90467aiosmtplib before 5.1.3 fails to properly validate email add…4
- CVE-2026-9047Improper handling of factor key state in the multi-factor au…7.6
Are you affected by CVE-2026-90456?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
