NONE · 0

CVE-2026-90454

A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags...

Vulnerability Description

A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, and the proxy configuration otherwise permits the request method those routes use. This allows an authenticated user on a deployment intended to be read-only to add or remove tags on stored session records.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-90454?

CVE-2026-90454 is a documented vulnerability. A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags...

How severe is CVE-2026-90454?

CVSS scoring is not yet available for CVE-2026-90454. Check NVD for updates.

Is there a patch for CVE-2026-90454?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.