CVE-2026-90454: Security vulnerability

Published Sep 11, 2026
·
Updated

A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, and the proxy configuration otherwise permits the request method those routes use. This allows an authenticated user on a deployment intended to be read-only to add or remove tags on stored session records.

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Malcolm to a version that resolves this vulnerability.

    Fixed in September 2026 or later

Event History

Sep 11, 2026
CVE Published
via MITRE·09:51 PM
Data Sourced
via MITRE·09:51 PM
RemedyDescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated user who can access the bundled packet-analysis component through a deployment configured for read-only exposure can exploit it. The issue affects stored session records that the user is able to reach through the exposed interface.

2

What access and request capability does exploitation require?

The attacker must be authenticated and able to send the HTTP method accepted by the proxy configuration for the tag-modification routes. No additional access requirement is stated.

3

Are read-only deployments fully protected by the intended route restrictions?

No. The deny pattern omits routes used to add or remove tags, while the proxy otherwise permits the method used by those routes.

4

How can I determine whether a deployment is affected?

Review the proxy's read-only route-deny pattern and confirm whether routes that modify tags on stored session records are excluded from that pattern. Also verify whether the proxy permits the request method used by those routes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203