Authentication Cookie Forgery Vulnerability in Packet-Analysis Component by Vendor
CVE-2026-90451

8.2HIGH

Key Information:

Vendor

Cisa

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-90451?

A security flaw exists in the packet-analysis component due to the inclusion of a default environment-configuration file that contains a hardcoded secret value for signing authentication cookies. If users deploy this example configuration without executing the necessary setup routine to regenerate the secret, they risk exposing their systems. Attackers familiar with this default configuration can forge authentication cookies, potentially gaining unauthorized access to sensitive functionalities within the component. To mitigate this vulnerability, it is crucial to avoid copying the example configuration file into the active environment and to ensure the secret values are properly generated and secured.

Affected Version(s)

Malcolm 0

Malcolm v26.06.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.