Authentication Bypass in Third-Party Administrative Interfaces of Vendor Product
CVE-2026-90449

6.9MEDIUM

Key Information:

Vendor

Cisa

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-90449?

A vulnerability exists when a specific authentication mode is configured, allowing a reverse proxy to directly forward requests to a bundled third-party administrative interface without enforcing the gateway’s own authentication. This design flaw means that access control over the administrative interface, which is crucial for managing the credential store tied to all other services, relies solely on the security mechanisms of the third-party interface. Any weakness in the authentication process of this interface poses a serious risk, as it can compromise the security of the entire deployment's credential store.

Affected Version(s)

Malcolm 0

Malcolm v26.06.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.