Description
An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.
Published: 2026-09-11
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Access Using Default Credentials
Action: Patch Immediately
AI Analysis

Impact

An example environment‑configuration file for a bundled inventory‑management component ships with a fixed, publicly‑known administrative password. If an installation copies this example file into active configuration without running the setup routine that regenerates credentials, the component’s administrative interface can be accessed by anyone who knows the default value. This flaw is a credential reuse weakness that can give an attacker full administrative control over the component, potentially compromising confidentiality, integrity, and availability.

Affected Systems

The vulnerability applies to any Malcolm instance distributed by CISA prior to the September 2026 release that includes the bundled inventory‑management component; users running those earlier versions must check whether they have deployed the example configuration file unchanged.

Risk and Exploitability

The CVSS score of 9.2 indicates critical severity, while the EPSS score of less than 1% shows a low probability of exploitation. The likely attack vector is over the network, as the administrative interface is exposed to anyone who can reach the component’s network endpoint. Exploiting the default administrative credentials would give full control over the inventory‑management component, creating high risk for environments that expose the interface to untrusted networks.

Generated by OpenCVE AI on September 15, 2026 at 21:16 UTC.

Remediation

Vendor Solution

The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.


OpenCVE Recommended Actions

  • Update to the latest Malcolm release (September 2026 or later) to remove the fixed password issue.
  • If updating is delayed, replace the example configuration file with a custom one that generates network controls and audit logs to restrict and monitor access to the inventory‑management component’s administrative interface, ensuring only trusted hosts can reach it.
  • Implement firewall rules or network segmentation to limit access to the inventory‑management component’s administrative interface to isolated management networks only.

Generated by OpenCVE AI on September 15, 2026 at 21:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Title Default Administration Credentials in Inventory‑Management Component Expose Malicious Access

Tue, 15 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Default Password in Inventory‑Management Component Enables Admin Access

Tue, 15 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Default Password in Inventory‑Management Component Enables Admin Access

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Default Administrative Password Exposed in Malcolm Inventory‑Management Component

Sun, 13 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisagov
Cisagov malcolm
Vendors & Products Cisagov
Cisagov malcolm

Sun, 13 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Default Administrative Password Exposed in Malcolm Inventory‑Management Component

Sun, 13 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Title Default Password in Inventory‑Management Component Exposes Administrative Interface

Sun, 13 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title Default Password in Inventory‑Management Component Exposes Administrative Interface

Sat, 12 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Default Administrative Password Disclosure in Malcolm Inventory‑Management Component

Sat, 12 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Default Administrative Password Disclosure in Malcolm Inventory‑Management Component

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.
Weaknesses CWE-1392
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-14T13:00:29.827Z

Reserved: 2026-09-11T21:00:09.301Z

Link: CVE-2026-90456

cve-icon Vulnrichment

Updated: 2026-09-14T12:57:15.262Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T22:16:47.993

Modified: 2026-09-18T19:39:09.490

Link: CVE-2026-90456

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:30:16Z

Weaknesses