CVE-2026-90456: Inventory-management component vulnerability
An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Malcolmto a version that resolves this vulnerability.Fixed in September 2026 or later
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments are exposed if they copy the bundled example environment-configuration file into active configuration and do not run the setup routine that regenerates credentials. The issue affects the administrative interface of the inventory-management component in that scenario.
What does an attacker need to exploit it?
An attacker needs awareness of the fixed, publicly known administrative password and access to the component's administrative interface. No unique credentials are required when the default value remains active.
How can administrators determine whether they are affected?
Check whether the active environment configuration was created by copying the bundled example file and whether the setup routine was subsequently run to regenerate credentials. If the example configuration remains active with its original administrative password, the deployment is affected.
What can be done if the setup routine cannot be run immediately?
Replace the fixed administrative password in the active configuration with a new non-default value and restrict access to the administrative interface. This addresses the exposure caused by retaining the publicly known credential.