CVE-2026-90940
novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. Attackers can trigger unauthorized cache invalidation by accessing the cache/refresh endpoint with the known default password, forcing unnecessary database queries to repopulate the cache.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.31%
- CWE
- CWE-1392
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- 201206030 novel-plus
Weakness type
Related vulnerabilities
- CVE-2024-12856 — Four-Faith Industrial Router adjust_sys_time OS Command Injection
- CVE-2025-8731 — TRENDnet TI-G160i/TI-PG102i/TPL-430AP SSH Service default credentials
- CVE-2025-55051 — CWE-1392: Use of Default Credentials
- CVE-2025-12218 — Weak Default Credentials
- CVE-2023-3703 — Proscend Advice ICR Series routers fw version 1.76
- CVE-2023-30801 — qBittorrent Web UI Default Credentials Lead to RCE
- CVE-2023-30603 — Hitron Technologies Inc. CODA-5310 - Using default credentials
- CVE-2023-49621 — A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system sta