SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90451

HIGH · CVSS 8.2 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

A vulnerability exists in an unspecified product due to the inclusion of a sample environment-configuration file containing a fixed, publicly-known secret used for signing authentication cookies. If this file is copied into active configuration without regenerating the secret, it allows attackers to forge valid authentication cookies, potentially compromising the integrity of the system. Organizations using this product should prioritize remediation to prevent unauthorized access and ensure secure cookie handling.

CVE
CVE-2026-90451
Severity
HIGH
CVSS
8.2
EPSS
0.33%

Original NVD Description

An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration without running the setup routine that regenerates the value will use the known default, allowing an attacker aware of the default to forge valid authentication cookies for that component.