NONE · 0

CVE-2026-90451

An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this exa...

Vulnerability Description

An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration without running the setup routine that regenerates the value will use the known default, allowing an attacker aware of the default to forge valid authentication cookies for that component.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-90451?

CVE-2026-90451 is a documented vulnerability. An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this exa...

How severe is CVE-2026-90451?

CVSS scoring is not yet available for CVE-2026-90451. Check NVD for updates.

Is there a patch for CVE-2026-90451?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.