ZeroHour

CVE-2026-90456

Hardcoded Default Admin Password Exposes Inventory-Management Component (CVE-2026-90456)

CVSS 4.0
9.2 critical
EPSS
Published
()
Modified
AI analysis

A bundled inventory-management component ships an example environment-configuration file containing a fixed, publicly known administrative password (CWE-1392, use of default credentials). The flaw is triggered when an operator copies that example file into the active configuration without running the setup routine that regenerates credentials, leaving the component's administrative interface protected only by the well-known default value. A remote, unauthenticated attacker who knows the default password can log into the administrative interface and gain full administrative control, consistent with the high confidentiality, integrity, and availability impacts in the 9.2 CVSS 4.0 score (note the 'attack requirements present' metric reflects the precondition that credentials were never regenerated). Only deployments that skipped the credential-regeneration setup are affected; the vendor, parent product, and affected versions are not named in the source data, and the advisory was assigned by CISA ICS-CERT. The flaw is not in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so exploitation has not been confirmed, though it would be trivial for anyone aware of the default credential.

What to do: Determine whether the bundled inventory-management component is deployed and whether its example environment-configuration file was copied into active configuration; if so, immediately replace the default administrative password with a strong, unique credential (or re-run the setup routine that regenerates credentials). Restrict network access to the component's administrative interface, monitor for successful logins using the known default value, and consult the CISA ICS-CERT advisory for patched releases, since no fixed version is specified in the source data.

Affected
Bundled inventory-management component shipped with an example environment-configuration file (parent product not identi
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.

Weakness
CWE-1392
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.