Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-90940— novel-plus through 5.3.3 Default Cache Management Password in the Front Portal

Quick assessment

Affected
201206030 novel-plus
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Novel Plus 插件 5.3.3 及之前版本在 端点中存在不安全的默认缓存管理密码。匿名用户可通过在 URL 路径中提供硬编码的默认密码值,从而触发非授权的缓存失效攻击。攻击者利用已知的默认密码访问 端点,可强制系统执行不必要的数据库查询以重新填充缓存,从而发起未经授权的缓存失效操作。

CVSS 5.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90940

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
novel-plus through 5.3.3 Default Cache Management Password in the Front Portal
Source: CVE Program / CVE List V5
Vulnerability Description
novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. Attackers can trigger unauthorized cache invalidation by accessing the cache/refresh endpoint with the known default password, forcing unnecessary database queries to repopulate the cache.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1392
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
201206030 novel-plus 0 ~ 5.3.3 -

II. Public POCs for CVE-2026-90940

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90940

登录查看更多情报信息。

Vendor Advisories for CVE-2026-90940 (1)

Proof of Concept for CVE-2026-90940 (1)

Vendor Pages for CVE-2026-90940 (1)

Other References for CVE-2026-90940 (3)

Same Patch Batch · 201206030 · 2026-09-14 · 3 CVEs total

CVE-2026-90939 6.5 MEDIUM novel-plus through 5.3.3 Missing Authorization on the Admin /sys/user/list Endpoint
CVE-2026-90941 4.3 MEDIUM novel-plus through 5.3.3 Missing Authorization on the Admin Book Download Endpoint

IV. Related Vulnerabilities

V. Comments for CVE-2026-90940

No comments yet


Leave a comment