CVE-2026-90456
An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.2
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.25%
- CWE
- CWE-1392
- Published
- 2026-09-11
- Last modified
- 2026-09-14
Affected products
- CISA Malcolm
- CISA Malcolm
Weakness type
Related vulnerabilities
- CVE-2024-12856 — Four-Faith Industrial Router adjust_sys_time OS Command Injection
- CVE-2025-8731 — TRENDnet TI-G160i/TI-PG102i/TPL-430AP SSH Service default credentials
- CVE-2025-55051 — CWE-1392: Use of Default Credentials
- CVE-2025-12218 — Weak Default Credentials
- CVE-2023-3703 — Proscend Advice ICR Series routers fw version 1.76
- CVE-2023-30801 — qBittorrent Web UI Default Credentials Lead to RCE
- CVE-2023-30603 — Hitron Technologies Inc. CODA-5310 - Using default credentials
- CVE-2023-49621 — A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system sta