CVE-2026-90453
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This allows an authenticated attacker to craft a request that causes another user's browser to be redirected to an arbitrary external destination after completing an upload.
| CWE | CWE-601 |
| Vendor | cisa |
| Product | malcolm |
| Published | Sep 11, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for cisa malcolm
Be the first to know when new unknown vulnerabilities affecting cisa malcolm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
CISA / Malcolm
0 < v26.06.0