WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH

CISA Malcolm

Small padlock on a network cable at a patch panelAI illustration
WORLDTECH illustration · AI-generated (Canva)

What happened

This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes arbitrary script in the context of the affected application and can redirect the user's browser to an arbitrary external site. Successful exploitation could allow an attacker to act with the compromised user's session privileges within the application.

View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm <v26.06.0 Product Status: known_affected Remediations Vendor fix The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed and execute arbitrary operating system commands with the privileges of that process.

Sources & evidence