Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Default Authentication Cookie Secret Enables Token Forgery in Packet-Analysis Component |
Tue, 15 Sep 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Fixed Secret in Example Configuration Enables Authentication Cookie Forgery for Packet‑Analysis Component |
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Fixed Secret in Example Configuration Enables Authentication Cookie Forgery for Packet‑Analysis Component |
Mon, 14 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Sep 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Malcolm Default Cookie Signing Secret Allows Authentication Forgery |
Sun, 13 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisagov
Cisagov malcolm |
|
| Vendors & Products |
Cisagov
Cisagov malcolm |
Sun, 13 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Malcolm Default Cookie Signing Secret Allows Authentication Forgery |
Sun, 13 Sep 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Default Cookie Signing Secret Allows Authentication Cookie Forgery |
Sun, 13 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Default Cookie Signing Secret Allows Authentication Cookie Forgery |
Sat, 12 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Default Secret Signing Key Lured into Production Enables Cookie Forgery |
Sat, 12 Sep 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Default Secret Signing Key Lured into Production Enables Cookie Forgery |
Fri, 11 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration without running the setup routine that regenerates the value will use the known default, allowing an attacker aware of the default to forge valid authentication cookies for that component. | |
| Weaknesses | CWE-1392 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-09-14T13:00:30.804Z
Reserved: 2026-09-11T21:00:09.301Z
Link: CVE-2026-90451
Updated: 2026-09-14T12:57:26.610Z
Status : Received
Published: 2026-09-11T22:16:47.343
Modified: 2026-09-14T13:19:28.710
Link: CVE-2026-90451
No data.
OpenCVE Enrichment
Updated: 2026-09-15T20:30:10Z