CVE-2026-90444
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed and execute arbitrary operating system commands with the privileges of that process. This allows an attacker to read and modify ingested log data, and could provide a foothold for further movement within the internal network.
| CWE | CWE-78 |
| Vendor | cisa |
| Product | malcolm |
| Published | Sep 11, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for cisa malcolm
Be the first to know when new unknown vulnerabilities affecting cisa malcolm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
CISA / Malcolm
0 < v26.06.0