---
id: CVE-2026-90452
title: >-
  Requests from the reverse proxy to the identity-provider service for token
  discovery, introspection, and credential exchange do not verify the identity
  provider's server certificate
summary: >-
  Requests from the reverse proxy to the identity-provider service for token
  discovery, introspection, and credential exchange do not verify the identity
  provider's server certificate. An attacker positioned on the network path
  between the…
severity: medium
cvss: 6
cvssVector: 'CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-295
vendor: CISA
product: Malcolm
affected:
  - Malcolm < v26.06.0
published: '2026-09-11'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:39:09.490'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90452'
references:
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
epss: 0.0013
epssPercentile: 0.02157
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T12:50:28.982744Z'
cvssSource: cna
ingestedAt: '2026-09-14T15:23:07.429Z'
---

## Overview

Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the proxy and the identity provider could impersonate the identity provider and issue forged authentication tokens accepted by the deployment.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
