THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-90449 — When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. All access control for this administrative i

[NVD] CVE-2026-90449 — When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. All access control for this administrative i

mednvdPublished 2026-09-11

CVE-2026-90449 CVSS: None Published: 2026-09-11T22:16:47.087

When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. All access control for this administrative interface, which manages the credential store used to gate

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-90449