CVE-2026-90451: Use of Default Credentials in Malcolm
An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration without running the setup routine that regenerates the value will use the known default, allowing an attacker aware of the default to forge valid authentication cookies for that component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Run the Malcolm setup routine to regenerate the authentication-cookie signing secret before copying the environment configuration into active use; do not use the example file's fixed publicly known secret.
Malcolm bundled packet-analysis component authentication-cookie signing secret = regenerated non-default secret
Event History
Frequently Asked Questions
Which deployments are affected?
Deployments are affected if the example environment-configuration file was copied into active configuration and the setup routine was not run to regenerate the cookie-signing secret. Deployments that use a regenerated secret are not described as affected.
What does an attacker need to exploit this issue?
An attacker needs knowledge of the fixed, publicly known default secret. With that value in use, they can forge authentication cookies accepted by the bundled packet-analysis component.
What can be done if patching is not immediately possible?
Run the setup routine that regenerates the authentication-cookie signing secret, rather than retaining the value from the example configuration file. Review the active environment configuration to determine whether it still contains the example value.