THREAT OPS › Threat News › [NVD] CVE-2026-90450 — The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered in this table is reachable by any authenti
[NVD] CVE-2026-90450 — The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered in this table is reachable by any authenti
CVE-2026-90450 CVSS: None Published: 2026-09-11T22:16:47.220
The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered in this table is reachable by any authenticated user regardless of their assigned role, and any new
Indicators of compromise
- CVE-2026-90450cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-90450