Description
novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. Attackers can trigger unauthorized cache invalidation by accessing the cache/refresh endpoint with the known default password, forcing unnecessary database queries to repopulate the cache.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized cache invalidation
Action: Patch
AI Analysis

Impact

An insecure default password is hard‑coded in the CacheController.refreshCache endpoint of the Novel Plus front portal. When an attacker supplies the known default value in the triggers a forced cache refresh. This causes the system to perform unnecessary database queries to rebuild the cache, potentially leading to resource exhaustion and degraded performance. The weakness is a hard‑coded credential, categorized as a hard‑coded password flaw.

Affected Systems

The vulnerability affects the Novel Plus web application, specifically versions up to and including 5.3.3. The source code for the affected releases contains a hard‑coded password in the CacheController and application configuration files, as shown in the public GitHub repository for version 5.3.3.

Risk and Exploitability

The CVSS score of 6.9 indicates medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only unauthenticated HTTP access to the /cache/refresh endpoint and knowledge of the publicly known default password, making it a straightforward attack for an adversary with network access to the application.

Generated by OpenCVE AI on September 15, 2026 at 13:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the latest available version of Novel Plus that removes or replaces the hard‑coded password; if a newer release is not yet available, apply it as soon as possible.
  • Restrict access to the /cache/refresh endpoint to authenticated users or clients behind a firewall; disable the endpoint if it is not required.
  • Monitor server logs for repeated cache refresh attempts and generate alerts when the default password is used.

Generated by OpenCVE AI on September 15, 2026 at 13:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared 201206030
201206030 novel-plus
Vendors & Products 201206030
201206030 novel-plus

Mon, 14 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. Attackers can trigger unauthorized cache invalidation by accessing the cache/refresh endpoint with the known default password, forcing unnecessary database queries to repopulate the cache.
Title novel-plus through 5.3.3 Default Cache Management Password in the Front Portal
First Time appeared Xxyopen
Xxyopen novel-plus
Weaknesses CWE-1392
CPEs cpe:2.3:a:xxyopen:novel-plus:*:*:*:*:*:*:*:*
Vendors & Products Xxyopen
Xxyopen novel-plus
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

201206030 Novel-plus
Xxyopen Novel-plus
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:01.943Z

Reserved: 2026-09-14T11:34:24.687Z

Link: CVE-2026-90940

cve-icon Vulnrichment

Updated: 2026-09-20T00:30:45.789Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T14:17:20.400

Modified: 2026-09-23T17:17:44.587

Link: CVE-2026-90940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:45:08Z

Weaknesses