CISA Malcolm
15 known vulnerabilities in CISA Malcolm, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-90457 CVSS 6.9 medium The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path…
- CVE-2026-90456 CVSS 9.2 critical An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative…
- CVE-2026-90455 CVSS 6.3 medium A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing…
- CVE-2026-90454 CVSS 5.3 medium A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable…
- CVE-2026-90453 CVSS 5.1 medium A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header…
- CVE-2026-90452 CVSS 6.0 medium Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify…
- CVE-2026-90451 CVSS 8.2 high An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a…
- CVE-2026-90450 CVSS 5.3 medium The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role…
- CVE-2026-90449 CVSS 6.9 medium When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative…
- CVE-2026-90448 CVSS 7.1 high A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without…
- CVE-2026-90447 CVSS 7.1 high A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a…
- CVE-2026-90446 CVSS 5.3 medium An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend…
- CVE-2026-90445 CVSS 7.1 high An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that…
- CVE-2026-90444 CVSS 8.7 high A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters…
- CVE-2026-90443 CVSS 5.3 medium A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does…