CVE-2026-90456
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.
| CWE | CWE-1392 |
| Vendor | cisa |
| Product | malcolm |
| Published | Sep 11, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for cisa malcolm
Be the first to know when new unknown vulnerabilities affecting cisa malcolm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
CISA / Malcolm
0 < v26.06.0