Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-90444: Malcolm file upload lets logged-in user run commands

CVE-2026-90444 · published 28 days ago
Summary

Malcolm's file‑transfer feature accepts any filename from a user who has logged in, and later builds a system command using that name. Because the filename is not checked, a malicious user can cause the program to execute any command it wants, potentially altering log data and gaining further access inside the network. Apply the vendor's update or restrict filenames to safe characters and limit the program's permissions.

What to do
  • Update cisa malcolm to version v26.06.0 or later.
Affected software
VendorProductAffected versions
cisa malcolm < v26.06.0
Original advisory text
OS Command Injection in Malcolm
A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed and execute arbitrary operating system commands with the privileges of that process. This allows an attacker to read and modify ingested log data, and could provide a foothold for further movement within the internal network.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
8.7 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-78OS Command Injection
Timeline
Published11 Sep 2026
Updated9 Oct 2026
First seen11 Sep 2026
Sources
CVE-2026-90444 · MITRE
Track software like this
Free during beta