CVE-2026-90447: Security vulnerability

Published Sep 11, 2026
·
Updated

A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service credential can set this header to route around the primary role-based authorization check and reach the alternate path's fixed, elevated role instead. This allows a low-privileged authenticated attacker who knows the shared credential to perform actions reserved for a higher-privileged role.

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Malcolm to a version that resolves this vulnerability.

    Fixed in September 2026 or later

Event History

Sep 11, 2026
CVE Published
via MITRE·09:48 PM
Data Sourced
via MITRE·09:48 PM
RemedyDescriptionWeakness

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

The attacker must be authenticated, have a low-privileged account, possess the shared service credential, and be able to supply the request header used by the routing rule.

2

Who is exposed to the authorization bypass?

Deployments are exposed where the routing rule chooses the authentication mechanism from a client-controlled request header and the alternate path assigns a fixed elevated role. Low-privileged authenticated users who know the shared credential can potentially reach actions reserved for that elevated role.

3

How can defenders identify attempted exploitation?

Review requests to the downstream service for the client-supplied header that controls authentication routing, especially when it selects the alternate authentication path. Investigate uses of the shared service credential by low-privileged accounts and any resulting elevated-role actions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203