Vulnary
← back to the feed
Critical· 9.2

CVE-2026-90456

A bundled inventory‑management component ships with an example configuration file that contains a fixed, publicly known administrative password. If a deployment copies this file into active use without running the setup routine that regenerates credentials, the component’s admin interface becomes accessible to anyone who knows the default password.

publishedSep 11, 2026
last modifiedSep 11, 2026
sourcesNVD
severity · cvss
9.2
critical · how bad it is
exploitation · epss
<1%
17th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Oct 26, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Installations of the bundled inventory‑management component that use the example configuration file without regenerating credentials or changing the password.

02

Real-world impact

An attacker who discovers the default password can log into the administrative interface, potentially modify inventory data, access sensitive information, or take control of the component’s functions.

03

Why this severity

The CVSS score of 9.2 reflects that the vulnerability allows attackers to gain full administrative access without authentication or user interaction, giving them high impact on confidentiality, integrity, and availability.

04

What to do about it

no official fix yet
interim mitigations
  • Do not deploy the example configuration file as‑is; run the setup routine to regenerate credentials or change the password. If the component is already deployed, immediately change the administrative password.

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

NVD description

05

Timeline

06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsPresent
Privileges requiredNone
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
CVE-2026-90456: A bundled inventory‑management component ships with an example configu · Vulnary