CISA flags RCE, auth bypass flaws in its own Malcolm tool
The audit tool CISA hands to critical infrastructure operators carries a high-severity OS command injection flaw and an authentication bypass that routes around its own role controls.
TL;DR
CISA's ICSA-26-254-01 discloses a dozen-plus vulnerability classes in Malcolm, the agency's free network traffic and log analysis suite, affecting all versions before v26.06.0. The worst is CVE-2026-90444, an 8.8 CVSS OS command injection: an authenticated user uploads a file whose name carries shell metacharacters, and a later automated process runs it with the privileges of that process. CVE-2026-90447 lets anyone holding a shared service credential set a request header to swap in the elevated fixed role. Fix is to v26.06.0 or later.
The advisory's own severity header reads CVSS v3 8.8, and the vulnerability list under it is long enough to fill a paragraph: stored and reflected XSS, OS command injection, path traversal, server-side request forgery, authentication bypass by spoofing, missing authorization, missing authentication for a critical function, default credentials, improper certificate validation, open redirect, a vulnerable third-party dependency, and password hashes with insufficient computational effort. Malcolm ships as Docker containers built around OpenSearch, so operators who treat it as a "read-only" viewer have been running a web application with all the exposure that implies.
What the two worst CVEs do
CVE-2026-90444 is the command injection. A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later builds and runs a system command from the uploaded file's name. CISA's own impact language says this allows an attacker to read and modify ingested log data and "could provide a foothold for further movement within the internal network." That's process-level remote code execution on a box that already has network visibility. The privilege requirement is what keeps it out of critical range: PR:L means the attacker needs a login.
CVE-2026-90447 is the bypass. A routing rule chooses between two authentication mechanisms for the same downstream service based on a client-supplied request header rather than anything the client can't control. A low-privileged user who knows the shared service credential flips that header, skips the primary role-based authorization check, and lands on the fixed elevated role. CVE-2026-90448 pairs with it: a deployment mode intended to expose only read access proxies API routes without restricting HTTP methods, so one route accepts a create-or-overwrite request with an attacker-chosen identifier using the application's own elevated backend credentials. The read-only mode isn't.
CVE-2026-90443 is the only flaw reachable without a login. The web interface reflects part of the request URL into script and hyperlink contexts without encoding. Unauthenticated, network-adjacent, but it needs a user to click a crafted link, which is why it scores 5.4 rather than 8.8.
Remediation and the awkward part
CISA's fix is unambiguous: update to the latest version, described in the advisory as September 2026 or later, corresponding to v26.06.0 and beyond. Every affected product line in the CSAF data reads Malcolm <v26.06.0. The advisory lists deployed sectors as Energy, Information Technology, and Water and Wastewater, deployed worldwide. If Malcolm sits on anything feeding CISA's free ICS visibility work or a state SOC's log pipeline, treat the upgrade as the patch, not a feature bump, and rotate any shared service credential that has circulated. Note that CISA does not state it has observed exploitation of these flaws, and nothing here appears in the KEV catalog on that basis.
The awkward part is timing and volume. This is not a one-off. Research and agency records show CISA published ICSA-26-230-01 on the same product barely a month earlier, covering allocation-of-resources, path traversal, unrestricted file upload and incorrect authorization flaws in <26.07.0 and <=26.07.1, also rated up to 8.8 by CVSS v3. CISA's version numbering means the fix for that advisory is a later build than the one this advisory recommends, so a shop that upgrades to v26.06.0 to clear these CVEs lands in a version that doesn't clear the August disclosures. Anyone operating Malcolm should validate against the current build rather than the minimum stated here.
What these two advisories together raise is a supply-chain question worth asking in plain terms: a tool that CISA recommends and distributes to critical infrastructure operators, and that many of those operators likely monitor less closely than commercial products because the vendor and the advisory service share a logo, has now disclosed two rounds of high-severity findings inside a month. CISA publishes the flaws the way it asks any vendor to. The gap the practitioner Monday reveals is that nobody was checking Malcolm's own supply chain the way the agency checks Schneider's or Siemens', and the "read-only deployment" label in the documentation described intent rather than enforcement.
Published ·Deep Fathom