CVE-2026-90451: Packet-analysis component vulnerability
An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration without running the setup routine that regenerates the value will use the known default, allowing an attacker aware of the default to forge valid authentication cookies for that component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Malcolmto a version that resolves this vulnerability.Fixed in September 2026
Event History
Frequently Asked Questions
Which deployments are affected?
Deployments are affected if the example environment-configuration file was copied into active configuration and the setup routine was not run to regenerate the cookie-signing secret. Deployments that use a regenerated secret are not described as affected.
What does an attacker need to exploit this issue?
An attacker needs knowledge of the fixed, publicly known default secret. With that value in use, they can forge authentication cookies accepted by the bundled packet-analysis component.
What can be done if patching is not immediately possible?
Run the setup routine that regenerates the authentication-cookie signing secret, rather than retaining the value from the example configuration file. Review the active environment configuration to determine whether it still contains the example value.