๐Ÿ” CVE Alert

CVE-2026-107337

HIGH 7.1

Cross-Site Request Forgery in Malcolm

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

The Malcolm kiosk Flask application exposes a POST /script_call/<script> endpoint with zero authentication and wildcard CORS (CORS(app)). An attacker can force the operator's browser to execute arbitrary management commands via CSRF, including control.py --wipe which permanently deletes all captured network traffic and forensic logs, or control.py --stop which blinds the security monitoring.

CWE CWE-352
Vendor cisa
Product malcolm
Published Oct 8, 2026
Last Updated Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for cisa malcolm

Be the first to know when new high vulnerabilities affecting cisa malcolm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High

Affected Versions

CISA / Malcolm
0 โ‰ค 26.07.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/cisagov/Malcolm/security/advisories/GHSA-w8gq-4v5x-xrrm github.com: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-280-01.json

Credits

Seth Grover