Security Advisory

CVE-2026-90456

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-11 21:52:17
Last updated 2026-09-11 21:52:17
Assigner icscert
CVSS score 9.2
State PUBLISHED

Description

An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.