Weak Password Hashing in Administrative Credential Management for Software
CVE-2026-90457

6.9MEDIUM

Key Information:

Vendor

Cisa

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-90457?

The vulnerability arises from the use of a weak hashing algorithm for storing administrative passwords, paired with insufficient file permissions that permit local users to access the hashed credentials. This inconsistency allows unauthorized parties to potentially recover the underlying password through offline techniques, compromising the integrity of administrative access across various systems.

Affected Version(s)

Malcolm 0

Malcolm v26.06.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.