SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90456

CRITICAL · CVSS 9.2 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

A critical vulnerability exists in an inventory-management component due to the inclusion of a publicly-known administrative password in a sample configuration file. If organizations deploy this example file without properly regenerating the credentials, they risk exposing the administrative interface to unauthorized access. Companies utilizing this component should prioritize immediate remediation to prevent potential exploitation.

CVE
CVE-2026-90456
Severity
CRITICAL
CVSS
9.2
EPSS
0.25%

Original NVD Description

An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.