Skip to content

Executive Summary

CISA Malcolm is affected by several vulnerabilities ranging from Cross-site Scripting and OS Command Injection to Server-Side Request Forgery (SSRF) and Authentication Bypass. These vulnerabilities exist across various versions of CISA Malcolm, specifically those prior to September 2026. Exploitable flaws include the ability for unauthenticated attackers to execute scripts, inject operating system commands, traverse directories via path manipulation, perform SSRF against backend services, bypass authentication, and misuse default credentials. Remediation involves updating the product to the latest version released in September 2026 or later. Specific CVEs detail issues related to input handling (CVE-2026-90443), file transfer command execution (CVE-2026-90444), path traversal (CVE-2026-90445), server request forgery (CVE-2026-90446), authentication bypass (CVE-2026-90447), and credential management (CVE-2026-90451, CVE-2026-90456).

Facts Only

* Affected product is CISA Malcolm.
* Vulnerabilities include Improper Neutralization of Input During Web Page Generation (Cross-site Scripting), OS Command Injection, Path Traversal, Server-Side Request Forgery (SSRF), Authentication Bypass by Spoofing, Missing Authorization, Missing Authentication for Critical Function, Incorrect Authorization, Use of Default Credentials, Improper Certificate Validation, and Dependency on Vulnerable Third-Party Component.
* Affected sectors include Energy, Information Technology, Water and Wastewater.
* CVE-2026-90443 involves reflecting request URL into a script context and allowing unauthenticated execution.
* CVE-2026-90444 allows authenticated attackers to execute operating system commands via file-transfer interfaces.
* CVE-2026-90445 allows authenticated attackers to write arbitrary files by traversing directory paths during file uploads.
* CVE-2026-90446 allows authenticated attackers to use application credentials against internal endpoints via path interpolation (SSRF).
* CVE-2026-90453 allows redirection based on the Referer header during file uploads.
* CVE-2026-90457 details a weakness in password hashing that permits offline recovery of passwords.
* Remediation requires updating to Malcolm version September 2026 or later.

Full Take

The sequence of vulnerabilities reveals a systemic failure across multiple security layers within the CISA Malcolm application, indicating challenges in consistently handling input validation, authorization checks, and credential management. The presence of both injection flaws (OS Command Injection, SSRF) alongside access control weaknesses (Missing Authorization, Incorrect Authorization) suggests that the system suffers from insufficient defense-in-depth; a failure in one layer facilitates exploitation across several others. Furthermore, the documented issues related to default credentials (CVE-2026-90451, CVE-2026-90456) and weak password hashing (CVE-2026-90457) point toward foundational flaws in configuration management and cryptographic practices that are often overlooked when focusing solely on application-layer logic. The proposed mitigation—updating the software—is a standard operational response, but the pattern suggests that the risk landscape is defined by systemic weaknesses rather than isolated bugs. The reliance on context-specific configurations for certificate validation (CVE-2026-90452) and authorization routing (CVE-2026-90447) implies complexity that increases the potential for misconfiguration, making rigorous adherence to principle of least privilege and strong default settings essential, rather than just patching known flaws. What are the assumptions driving the complexity in configuration management within this system? How can organizations ensure that updates address the root cause of these interwoven input and access control failures rather than just patching the symptoms?

From the original · CISA ICS Advisories

Summary The following versions of CISA Malcolm are affected: - Malcolm | CVSS | Vendor | Equipment | Vulnerabilities | |---|---|---|---| | v3 8.8 | CISA | CISA Malcolm | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Limitation of a Pathname to a Restricted…
Read the full story at cisa.gov

Sentinel — Human

Confidence

This text is a highly structured, fact-based enumeration of cybersecurity vulnerabilities for a specific software product. Its precision suggests it originates from an authoritative source, likely CISA, rather than general synthetic content.

Signals Detected
low severity: Sentence length variance is moderate; structure is highly data-driven and repetitive.
low severity: High fluency but lacks emotional cadence; purely technical enumeration without editorial voice.
medium severity: Perfect, rigid structure matching a vulnerability advisory format; heavy reliance on structured tables and metrics.
low severity: The content is a highly specific technical security bulletin, which relies on verifiable source data (CVEs, CVSS scores).
Human Indicators
Presence of detailed, specific vulnerability identifiers (CVEs) and standardized CVSS metrics suggests direct reporting from a technical body.
The concluding 'Acknowledgments' and 'Recommended Practices' sections include high-level strategic advice relevant to critical infrastructure security, typical of official advisories.
CISA Malcolm | Huntaegis