Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 11 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the proxy and the identity provider could impersonate the identity provider and issue forged authentication tokens accepted by the deployment. | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-09-11T21:51:08.628Z
Reserved: 2026-09-11T21:00:09.301Z
Link: CVE-2026-90452
No data.
Status : Received
Published: 2026-09-11T22:16:47.473
Modified: 2026-09-11T22:16:47.473
Link: CVE-2026-90452
No data.
OpenCVE Enrichment
No data.
-
CWE-295
Improper Certificate Validation