CVE-2026-90940

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. Attackers can trigger unauthorized cache invalidation by accessing the cache/refresh endpoint with the known default password, forcing unnecessary database queries to repopulate the cache.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-14 14:17

Updated : 2026-09-14 14:17


NVD link : CVE-2026-90940

Mitre link : CVE-2026-90940

CVE.ORG link : CVE-2026-90940


JSON object : View

Products Affected

No product.

CWE
CWE-1392

Use of Default Credentials