Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-90456: Malcolm inventory component exposed with default admin password

CVE-2026-90456 · published 28 days ago
Summary

The Malcolm inventory-management part includes a sample configuration file that contains a known default admin password. If this file is used without changing the password, anyone who knows the default can access the administrative interface. Change the password to a unique, strong one before putting the configuration into use.

What to do
  • Update cisa malcolm to version v26.06.0 or later.
Affected software
VendorProductAffected versions
cisa malcolm < v26.06.0
Original advisory text
Use of default credentials in Malcolm
An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-1392Use of Default Credentials
Timeline
Published11 Sep 2026
Updated9 Oct 2026
First seen11 Sep 2026
Sources
CVE-2026-90456 · MITRE
Track software like this
Free during beta