PatchSiren

201206030 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM 201206030 CVE published 2026-09-14

CVE-2026-90940

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint, allowing anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. This insecure default password can lead to unauthorized cache invalidation, potentially causing increased database queries and performance impacts. Defenders managing [truncated]