MEDIUMVulnerability

CVE-2026-90940

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. Attackers can trigger unauthorized cache invalidation by accessing the cache/refresh endpoint with the known default password, forcing unnecessary database queries to repopulate the cache.

Properties

severity
MEDIUM
score
5.3
cve_id
CVE-2026-90940
signal_observed_at
2026-09-23T22:45:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
published_at
2026-09-14T14:17:20.400
last_modified
2026-09-23T17:17:44.587

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Use of Default Credentials

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90940 — Ninja Signal Threat Intelligence | Ninja Signal