MEDIUM
201206030
CVE published 2026-09-14
CVE-2026-90940
novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint, allowing anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. This insecure default password can lead to unauthorized cache invalidation, potentially causing increased database queries and performance impacts. Defenders managing [truncated]