CVE-2026-90456
Received Received - Intake

Default Admin Password in Inventory Management Component

Vulnerability report for CVE-2026-90456, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: ICS-CERT

Description

An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1392 The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an example configuration file for an inventory-management component that includes a fixed, publicly-known administrative password. If this file is copied into active configuration without running the setup routine to regenerate credentials, the component's administrative interface becomes accessible to anyone aware of the default password.

Detection Guidance

Check for the presence of example environment-configuration files in your inventory-management component. Search for files containing the default administrative password mentioned in the component's documentation. Inspect configuration files for hardcoded credentials or default passwords.

Impact Analysis

An attacker could exploit this to gain administrative access to the inventory-management component, potentially allowing them to manipulate data, disrupt operations, or escalate privileges within the system.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating confidentiality requirements in GDPR and HIPAA. Non-compliance may result in legal penalties, fines, or reputational damage.

Mitigation Strategies

Remove or disable the example configuration file if it contains default credentials. Regenerate all administrative passwords using the setup routine provided by the component. Ensure no active configuration uses default or example credentials.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90456. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart