Junglewise Threat Intelligence

CVE-2026-90457: Weak password hashing and insecure credential storage

CVE-2026-90457 · Severity: info · Published 2026-09-11

Executive brief

Administrative credentials are protected using a weak hashing algorithm with overly permissive file permissions, allowing local users or those with backup access to read the password hash. This contradicts stronger protections used on another authentication path. An attacker with local system access or a backup of the configuration could recover the administrative password offline, compromising security across all systems that use it.

Technical details

The vulnerability involves inconsistent credential protection: an administrative password is hashed using a comparatively weak, fast algorithm (such as MD5 or SHA-1) in a credential store backing one authentication path, and the file containing this hash is written with world-readable or overly permissive file permissions. A separate authentication path uses a stronger hashing algorithm for the same password. An attacker with local file system access (local user, SSH access, or via configuration backup) can read the poorly protected hash file and perform offline password cracking using dictionary attacks or rainbow tables. Successfully recovering the password would grant administrative access across all authentication paths. Mitigation requires switching to consistent, modern password hashing algorithms (bcrypt, scrypt, Argon2) and restricting file permissions to root/administrative users only.

References