cbcvebase.

Cisa Malcolm vulnerabilities

15 known vulnerabilities affecting cisa/malcolm.

Total CVEs
15
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM11LOW2

Vulnerabilities

Page 1 of 1
CVE-2026-90444P2HIGHCVSS 8.8fixed in v26.06.02026-09-11
CVE-2026-90444 [HIGH] CWE-78 CVE-2026-90444: A file-transfer interface that requires valid credentials accepts attacker-controlled filenames with A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed and execute arbitrary operating system commands with the privileges of that
nvd
CVE-2026-90456P3HIGHCVSS 8.1fixed in v26.06.02026-09-11
CVE-2026-90456 [HIGH] CWE-1392 CVE-2026-90456: An example environment-configuration file for a bundled inventory-management component ships with a An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of t
nvd
CVE-2026-90445P3MEDIUMCVSS 6.5fixed in v26.06.02026-09-11
CVE-2026-90445 [MEDIUM] CWE-22 CVE-2026-90445: An interface that accepts file uploads from authenticated users extracts the contents of uploaded ar An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries traverse outside the destination directory, causing the extraction process to
nvd
CVE-2026-90449P3MEDIUMCVSS 6.5fixed in v26.06.02026-09-11
CVE-2026-90449 [MEDIUM] CWE-306 CVE-2026-90449: When a particular authentication mode is configured, the reverse proxy forwards requests for a bundl When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. All access control for this administrative interface, which manages the credential store used to gate every other s
nvd
CVE-2026-90447P3MEDIUMCVSS 6.5fixed in v26.06.02026-09-11
CVE-2026-90447 [MEDIUM] CWE-290 CVE-2026-90447: A routing rule selects between two different authentication mechanisms for the same downstream servi A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service credential can set this header to route around the primary role-based authorizati
nvd
CVE-2026-90448P3MEDIUMCVSS 6.5fixed in v26.06.02026-09-11
CVE-2026-90448 [MEDIUM] CWE-862 CVE-2026-90448: A deployment mode intended to expose only read access to stored data proxies a set of application pr A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route accepts a request that creates or overwrites a stored record, including an attacker-chosen identifier, using the application's own elevated backend creden
nvd
CVE-2026-90451P3MEDIUMCVSS 5.9fixed in v26.06.02026-09-11
CVE-2026-90451 [MEDIUM] CWE-1392 CVE-2026-90451: An example environment-configuration file ships with a fixed, publicly-known secret value used to si An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration without running the setup routine that regenerates the value will use the known default, allowing an attacker awar
nvd
CVE-2026-90443P4MEDIUMCVSS 5.4fixed in v26.06.02026-09-11
CVE-2026-90443 [MEDIUM] CWE-79 CVE-2026-90443: A web interface reflects a portion of the request URL into a script context and a hyperlink attribut A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes arbitrary script in the context of the affected application and can redire
nvd
CVE-2026-90457P4MEDIUMCVSS 6.2fixed in v26.06.02026-09-11
CVE-2026-90457 [MEDIUM] CWE-916 CVE-2026-90457: The administrative password is hashed using a comparatively weak, fast algorithm for the credential The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissions allowing it to be read by any local user. This is inconsistent with a separate, stronger hashing algorithm used for the same password on another authen
nvd
CVE-2026-90446P4MEDIUMCVSS 4.3fixed in v26.06.02026-09-11
CVE-2026-90446 [MEDIUM] CWE-918 CVE-2026-90446: An application programming interface endpoint accepts a user-supplied value and interpolates it dire An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows an authenticated attacker to substitute an arbitrary backend path, causing the application's own elevated service
nvd
CVE-2026-90452P4MEDIUMCVSS 5.3fixed in v26.06.02026-09-11
CVE-2026-90452 [MEDIUM] CWE-295 CVE-2026-90452: Requests from the reverse proxy to the identity-provider service for token discovery, introspection, Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the proxy and the identity provider could impersonate the identity provider and issue forged authentication tokens ac
nvd
CVE-2026-90454P4MEDIUMCVSS 4.3fixed in v26.06.02026-09-11
CVE-2026-90454 [MEDIUM] CWE-862 CVE-2026-90454: A deployment mode intended to expose only read access to a bundled packet-analysis component's inter A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, and the proxy configuration otherwise permits the request method those routes use. This allows an authenticated us
nvd
CVE-2026-90450P4MEDIUMCVSS 4.3fixed in v26.06.02026-09-11
CVE-2026-90450 [MEDIUM] CWE-863 CVE-2026-90450: The application's role-authorization lookup defaults to granting access when a request handler's nam The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered in this table is reachable by any authenticated user regardless of their assigned role, and any newly added handl
nvd
CVE-2026-90453P4LOWCVSS 3.5fixed in v26.06.02026-09-11
CVE-2026-90453 [LOW] CWE-601 CVE-2026-90453: A file-upload handler redirects the authenticated client's browser to a URL taken directly from that A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This allows an authenticated attacker to craft a request that causes another user's browser to be redirected to an arbitrary external destination after completing
nvd
CVE-2026-90455P4LOWCVSS 3.7fixed in v26.06.02026-09-11
CVE-2026-90455 [LOW] CWE-1395 CVE-2026-90455: A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilit A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a single fixed, trusted vendor URL at initialization and does not process a
nvd
Cisa Malcolm vulnerabilities | cvebase