Impact
Malcolm's file‑upload component accepts any file type; the default allow‑list is empty so the file type check is bypassed. The component preserves the .php extension of uploaded files, stores them under /var/www/upload/server/php/files, and nginx forwards requests ending in .php to php‑fpm, executing the uploaded code under the www‑data user. This flaw is CWE‑434, an unrestricted upload of files with a dangerous type, allowing an authenticated user with the ROLE_UPLOAD role to run arbitrary PHP code, which compromises confidentiality, integrity, and availability of the system. Based on the description, the attack vector is an authenticated upload by a user with the ROLE_UPLOAD permission.
Affected Systems
All Malcolm releases from cisagov before version 26.06.1 are affected. The vulnerability resides in the file‑upload endpoint POST /server/php/submit.php, with uploaded files stored in /var/www/upload/server/php/files; users granted the granular ROLE_UPLOAD role in RBAC mode can upload files, a role intended only for capture files.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, but the EPSS score of less than 1% indicates a very low current likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. An attacker must authenticate as a user with the ROLE_UPLOAD permission, upload a malicious PHP file, and later trigger its execution with a GET request. The highest risk occurs when RBAC is not hardened and the upload endpoint remains reachable to users with limited permissions.
OpenCVE Enrichment