CVE-2026-90456
9.2CISA · Malcolm
A default administrative password in a bundled inventory management component allows unauthenticated access to the administrative interface if the setup routine is not correctly executed.
Executive summary
CISA Malcolm contains a critical vulnerability involving default credentials that enables unauthorized administrative access, posing a significant risk of full system compromise.
Vulnerability
This vulnerability, categorized as CWE-1392 (Use of Default Credentials), occurs when an example configuration file containing a known password is used in production without running the required credential regeneration setup. Because the CVSS vector indicates no privileges are required (PR:N) and the attack vector is network-based (AV:N), an unauthenticated attacker can gain full administrative control.
Business impact
The use of default credentials creates an immediate pathway for unauthorized actors to gain administrative access to the inventory management component. Given the CVSS score of 9.2, this vulnerability allows for complete confidentiality, integrity, and availability impact on the affected system. Exploitation could lead to unauthorized data exfiltration, system manipulation, and potential lateral movement within the network.
Remediation
Immediate Action: Update your instance of CISA Malcolm to version v26.06.0 or later to ensure the default credential issue is addressed.
Proactive Monitoring: Review system access logs for suspicious administrative logins or unauthorized configuration changes, particularly from unknown IP addresses.
Compensating Controls: If an immediate update is not possible, restrict network access to the administrative interface using a firewall or VPN to ensure only authorized personnel can reach the management port.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a critical security oversight that can be easily exploited by malicious actors. Organizations should prioritize updating to the latest version of CISA Malcolm immediately. If you have deployed the software using default configurations, you must verify that the credential regeneration process has been successfully completed to mitigate this risk.
More CISA CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section