Environment Configuration Vulnerability in Inventory Management Component by CISAgov
CVE-2026-90456

9.2CRITICAL

Key Information:

Vendor

Cisa

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-90456?

A security vulnerability exists in the inventory management component where an example configuration file is shipped with a publicly-known administrative password. If this example file is mistakenly copied into the active configuration without executing the setup procedure to regenerate the credentials, the administrative interface becomes vulnerable to unauthorized access. This issue emphasizes the importance of secure configuration practices to prevent exposure of sensitive administrative access.

Affected Version(s)

Malcolm 0

Malcolm v26.06.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.