CVE-2026-90451: Packet-analysis component vulnerability

Published Sep 11, 2026
·
Updated

An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration without running the setup routine that regenerates the value will use the known default, allowing an attacker aware of the default to forge valid authentication cookies for that component.

Affected Software

1 affected component
packet-analysis component

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Malcolm to a version that resolves this vulnerability.

    Fixed in September 2026

Event History

Sep 11, 2026
CVE Published
via MITRE·09:50 PM
Data Sourced
via MITRE·09:50 PM
RemedyDescriptionWeakness

Frequently Asked Questions

1

Which deployments are affected?

Deployments are affected if the example environment-configuration file was copied into active configuration and the setup routine was not run to regenerate the cookie-signing secret. Deployments that use a regenerated secret are not described as affected.

2

What does an attacker need to exploit this issue?

An attacker needs knowledge of the fixed, publicly known default secret. With that value in use, they can forge authentication cookies accepted by the bundled packet-analysis component.

3

What can be done if patching is not immediately possible?

Run the setup routine that regenerates the authentication-cookie signing secret, rather than retaining the value from the example configuration file. Review the active environment configuration to determine whether it still contains the example value.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203