CVE-2026-90443
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes arbitrary script in the context of the affected application and can redirect the user's browser to an arbitrary external site. Successful exploitation could allow an attacker to act with the compromised user's session privileges within the application.
| CWE | CWE-79 |
| Vendor | cisa |
| Product | malcolm |
| Published | Sep 11, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for cisa malcolm
Be the first to know when new unknown vulnerabilities affecting cisa malcolm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
CISA / Malcolm
0 < v26.06.0