CVE-2026-90456

An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-11 22:16

Updated : 2026-09-14 13:19


NVD link : CVE-2026-90456

Mitre link : CVE-2026-90456

CVE.ORG link : CVE-2026-90456


JSON object : View

Products Affected

No product.

CWE
CWE-1392

Use of Default Credentials