CVE-2026-90447
A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service credential can set this header to route around the primary role-based authorization check and reach the alternate path's fixed, elevated role instead. This allows a low-privileged authenticated attacker who knows the shared credential to perform actions reserved for a higher-privileged role.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.27%
- CWE
- CWE-290
- Published
- 2026-09-11
- Last modified
- 2026-09-14
Affected products
- CISA Malcolm
- CISA Malcolm
Weakness type
Related vulnerabilities
- CVE-2026-25938 — FUXA Unauthenticated Remote Code Execution in Node-RED Integration
- CVE-2026-27478 — Unity Catalog has a JWT Issuer Validation Bypass Allows Complete User Impersonation
- CVE-2026-33654 — Zero-Click Indirect Prompt Injection and Authentication Bypass via Email Polling
- CVE-2026-31889 — Shopware has a potential take over of app credentials
- CVE-2026-33661 — WeChat Pay callback signature verification bypassed when Host header is localhost
- CVE-2026-76423 — Cisco ISE API Authentication Bypass Vulnerability
- CVE-2026-6213 — Remote Spark SparkView RCE
- CVE-2026-54782 — CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation