Access Control Weakness in Packet-Analysis Component by Cisco
CVE-2026-90454
5.3MEDIUM
What is CVE-2026-90454?
An access control vulnerability exists in Cisco's packet-analysis component where a misconfigured deployment allows authenticated users to modify tags in stored session records. The intended read-only access is undermined due to a failure in properly restricting write-capable routes, enabling the manipulation of session tags, which could lead to unauthorized changes in session data.
Affected Version(s)
Malcolm 0
Malcolm v26.06.0
