Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-90456: Malcolm inventory component exposed with default admin password
CVE-2026-90456 · published 28 days ago
Summary
The Malcolm inventory-management part includes a sample configuration file that contains a known default admin password. If this file is used without changing the password, anyone who knows the default can access the administrative interface. Change the password to a unique, strong one before putting the configuration into use.
What to do
- Update cisa malcolm to version v26.06.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| cisa | malcolm | < v26.06.0 |
Original advisory text
Use of default credentials in Malcolm
An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.
References
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90456... Vendor Advisory
- https://github.com/cisagov/Malcolm Product
- https://nvd.nist.gov/vuln/detail/CVE-2026-90456 Vendor Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-1392Use of Default Credentials
Timeline
Published11 Sep 2026
Updated9 Oct 2026
First seen11 Sep 2026
Track software like this
Free during beta