NewsSecurity Vulnerabilities

Critical Vulnerability Found in CISA Malcolm (CVE-2026-90456)

A critical security vulnerability has been discovered in CISA’s Malcolm network traffic analysis platform that could expose an administrative interface to unauthorised attackers.

Tracked as CVE-2026-90456, the vulnerability involves a publicly known, fixed administrative password included in an example environment-configuration file for a bundled inventory-management component. The flaw was published on 11 September 2026 and has been assigned a CVSS v4.0 score of 9.2, placing it in the critical severity category.

The problem occurs when administrators copy the example configuration into an active deployment without completing the setup process that generates new credentials. In that situation, the administrative interface can remain protected by the known default password.

An attacker who knows the default credential could potentially gain administrative access to the affected inventory-management component. Depending on how Malcolm is deployed and what access the component provides, this could have serious consequences for confidentiality, integrity and availability.

The vulnerability has been classified as CWE-1392, which covers the use of default credentials.

Malcolm versions affected

The vulnerability affects CISA Malcolm releases before version 26.06.0. Version 26.06.0 is listed as unaffected.

Administrators running older versions should therefore upgrade to version 26.06.0 or later and ensure that any administrative credentials are changed from default values.

CISA’s advisory information also highlights the importance of following the normal setup procedure rather than deploying the example configuration unchanged.

Why the vulnerability matters

Default passwords remain a significant security risk, particularly when software is deployed in environments where management interfaces can be reached remotely.

Malcolm is designed for network traffic analysis and security monitoring, meaning a compromised installation could provide an attacker with access to systems handling potentially sensitive network information.

There is currently no indication that CVE-2026-90456 has been added to the CISA Known Exploited Vulnerabilities catalogue, and available vulnerability intelligence does not currently report exploitation in the wild.

However, the relatively simple nature of the issue and its critical CVSS rating mean organisations using affected Malcolm releases should treat the vulnerability as a priority.

Administrators should upgrade Malcolm, avoid using example configuration files directly in production, regenerate credentials during setup and review existing deployments for the presence of the known default password.

CVE: CVE-2026-90456
Product: CISA Malcolm
Affected versions: Before 26.06.0
Fixed version: 26.06.0
Severity: Critical
CVSS v4.0: 9.2
CWE: CWE-1392 – Use of Default Credentials
Published: 11 September 2026

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.