Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-90444: Malcolm file upload lets logged-in user run commands
CVE-2026-90444 · published 28 days ago
Summary
Malcolm's file‑transfer feature accepts any filename from a user who has logged in, and later builds a system command using that name. Because the filename is not checked, a malicious user can cause the program to execute any command it wants, potentially altering log data and gaining further access inside the network. Apply the vendor's update or restrict filenames to safe characters and limit the program's permissions.
What to do
- Update cisa malcolm to version v26.06.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| cisa | malcolm | < v26.06.0 |
Original advisory text
OS Command Injection in Malcolm
A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed and execute arbitrary operating system commands with the privileges of that process. This allows an attacker to read and modify ingested log data, and could provide a foothold for further movement within the internal network.
References
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90444... Vendor Advisory
- https://github.com/cisagov/Malcolm Product
- https://nvd.nist.gov/vuln/detail/CVE-2026-90444 Vendor Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-78OS Command Injection
Timeline
Published11 Sep 2026
Updated9 Oct 2026
First seen11 Sep 2026
Track software like this
Free during beta