Authentication Bypass in Third-Party Administrative Interfaces of Vendor Product
CVE-2026-90449
6.9MEDIUM
What is CVE-2026-90449?
A vulnerability exists when a specific authentication mode is configured, allowing a reverse proxy to directly forward requests to a bundled third-party administrative interface without enforcing the gateway’s own authentication. This design flaw means that access control over the administrative interface, which is crucial for managing the credential store tied to all other services, relies solely on the security mechanisms of the third-party interface. Any weakness in the authentication process of this interface poses a serious risk, as it can compromise the security of the entire deployment's credential store.
Affected Version(s)
Malcolm 0
Malcolm v26.06.0
