CVE-2026-90456: Inventory-management component vulnerability

Published Sep 11, 2026
·
Updated

An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.

Affected Software

1 affected component
inventory-management component

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Malcolm to a version that resolves this vulnerability.

    Fixed in September 2026 or later

Event History

Sep 11, 2026
CVE Published
via MITRE·09:52 PM
Data Sourced
via MITRE·09:52 PM
RemedyDescriptionWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments are exposed if they copy the bundled example environment-configuration file into active configuration and do not run the setup routine that regenerates credentials. The issue affects the administrative interface of the inventory-management component in that scenario.

2

What does an attacker need to exploit it?

An attacker needs awareness of the fixed, publicly known administrative password and access to the component's administrative interface. No unique credentials are required when the default value remains active.

3

How can administrators determine whether they are affected?

Check whether the active environment configuration was created by copying the bundled example file and whether the setup routine was subsequently run to regenerate credentials. If the example configuration remains active with its original administrative password, the deployment is affected.

4

What can be done if the setup routine cannot be run immediately?

Replace the fixed administrative password in the active configuration with a new non-default value and restrict access to the administrative interface. This addresses the exposure caused by retaining the publicly known credential.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203