novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. Attackers can trigger unauthorized cache invalidation by accessing the cache/refresh endpoint with the known default password, forcing unnecessary database queries to repopulate the cache.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 14:17
Updated : 2026-09-14 14:17
NVD link : CVE-2026-90940
Mitre link : CVE-2026-90940
CVE.ORG link : CVE-2026-90940
JSON object : View
Products Affected
No product.
CWE
CWE-1392
Use of Default Credentials
