THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-90447 — A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service credential

[NVD] CVE-2026-90447 — A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service credential

mednvdPublished 2026-09-11

CVE-2026-90447 CVSS: None Published: 2026-09-11T22:16:46.797

A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service credential can set this header to route around the primary role-bas

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-90447