---
id: CVE-2026-90449
title: >-
  When a particular authentication mode is configured, the reverse proxy
  forwards requests for a bundled third-party administrative interface directly
  to that interface without applying the gateway's own authentication
  requirement first
summary: >-
  When a particular authentication mode is configured, the reverse proxy
  forwards requests for a bundled third-party administrative interface directly
  to that interface without applying the gateway's own authentication
  requirement first. A…
severity: medium
cvss: 6.9
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-306
vendor: CISA
product: Malcolm
affected:
  - Malcolm < v26.06.0
published: '2026-09-11'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:40:31.053'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90449'
references:
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
epss: 0.0031
epssPercentile: 0.24107
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-14T16:12:03.494558Z'
cvssSource: cna
ingestedAt: '2026-09-14T11:11:19.875Z'
---

## Overview

When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. All access control for this administrative interface, which manages the credential store used to gate every other service in the deployment, is delegated entirely to that third-party interface's own login mechanism. Any authentication weakness in that bundled interface would compromise the credential store protecting the rest of the deployment.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
