Access Control Flaw in Vendor Product Exposes User Roles
CVE-2026-90450
5.3MEDIUM
What is CVE-2026-90450?
This vulnerability allows any authenticated user to access request handlers that are not explicitly defined in the role requirement table of the application. As a result, newly created request handlers default to being accessible by all authenticated users, effectively bypassing intended access controls. This poses significant security risks, as unauthorized users may exploit these fail-open configurations to gain improper access.
Affected Version(s)
Malcolm 0
Malcolm v26.06.0
