SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90447

HIGH · CVSS 7.1 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The vulnerability allows authenticated users with shared service credentials to manipulate a request header, bypassing primary role-based authorization checks and gaining access to elevated privileges. This can lead to unauthorized actions typically reserved for higher-privileged roles, posing significant risks to the integrity and security of the affected services. Organizations utilizing this routing mechanism should prioritize remediation to prevent potential exploitation by low-privileged attackers.

CVE
CVE-2026-90447
Severity
HIGH
CVSS
7.1
EPSS
0.27%

Original NVD Description

A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service credential can set this header to route around the primary role-based authorization check and reach the alternate path's fixed, elevated role instead. This allows a low-privileged authenticated attacker who knows the shared credential to perform actions reserved for a higher-privileged role.