Improper Certificate Validation in Identity Provider for Proxy Services
CVE-2026-90452

6MEDIUM

Key Information:

Vendor

Cisa

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-90452?

The vulnerability arises when requests from a reverse proxy to an identity provider service for token discovery, introspection, and credential exchange fail to verify the identity provider's server certificate. This oversight allows an adversary situated on the network path between the proxy and the identity provider to impersonate the latter. Consequently, the attacker could potentially issue forged authentication tokens, which would be accepted by the deployed service, leading to unauthorized access and compromising sensitive information.

Affected Version(s)

Malcolm 0

Malcolm v26.06.0

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.