THREAT OPS › Threat News › [NVD] CVE-2026-90446 — An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows an authenticated attacker to substitute an
[NVD] CVE-2026-90446 — An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows an authenticated attacker to substitute an
CVE-2026-90446 CVSS: None Published: 2026-09-11T22:16:46.653
An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows an authenticated attacker to substitute an arbitrary backend path, causing the application's own ele
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-90446cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-90446