CVE-2026-90454
Received Received - Intake

Read-Only Mode Bypass in Packet Analysis Component

Vulnerability report for CVE-2026-90454, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: ICS-CERT

Description

A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, and the proxy configuration otherwise permits the request method those routes use. This allows an authenticated user on a deployment intended to be read-only to add or remove tags on stored session records.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a deployment mode meant to restrict access to read-only operations for a packet-analysis component. However, the configuration fails to block routes that modify tags on stored session records. An authenticated user can exploit this to add or remove tags despite the read-only intent.

Impact Analysis

If you use this system in a read-only deployment, an attacker with authenticated access could modify session record tags. This could lead to unauthorized changes in data classification or metadata, potentially affecting analysis or compliance reporting.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized modifications to session records. For GDPR, it may affect data integrity and audit trails. For HIPAA, it could compromise protected health information integrity if tags relate to sensitive data handling.

Mitigation Strategies

Review proxy configurations to ensure write-capable routes modifying tags are explicitly denied. Audit session records for unauthorized tag changes and restrict authenticated user permissions to read-only access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90454. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart