CVE-2026-90456
A bundled inventory‑management component ships with an example configuration file that contains a fixed, publicly known administrative password. If a deployment copies this file into active use without running the setup routine that regenerates credentials, the component’s admin interface becomes accessible to anyone who knows the default password.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Installations of the bundled inventory‑management component that use the example configuration file without regenerating credentials or changing the password.
Real-world impact
An attacker who discovers the default password can log into the administrative interface, potentially modify inventory data, access sensitive information, or take control of the component’s functions.
Why this severity
The CVSS score of 9.2 reflects that the vulnerability allows attackers to gain full administrative access without authentication or user interaction, giving them high impact on confidentiality, integrity, and availability.
What to do about it
- ›Do not deploy the example configuration file as‑is; run the setup routine to regenerate credentials or change the password. If the component is already deployed, immediately change the administrative password.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
NVD description