Description
Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array by default (`file-upload/php/config.php:16`), so the type check is a no-op and every extension is accepted. The filename sanitizer keeps the `.php` extension intact. Committed files land in `/var/www/upload/server/php/files` (`file-upload/php/config.php:7`), and the component's nginx routes any URL ending in `.php` to php-fpm. An authenticated `GET /server/php/files/<name>.php` then executes the uploaded code as `www-data`. Prior to version 26.06.1, in RBAC mode, the upload endpoint is reachable by the granular `ROLE_UPLOAD` role (`nginx/lua/nginx_auth_helpers.lua:71`), a role intended only for submitting capture files. As a result, a user holding the upload-only role runs arbitrary PHP as `www-data` inside the file-upload container. Version 26.06.1 fixes the issue.
Published: 2026-08-11
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Malcolm's file‑upload component accepts any file type; the default allow‑list is empty so the file type check is bypassed. The component preserves the .php extension of uploaded files, stores them under /var/www/upload/server/php/files, and nginx forwards requests ending in .php to php‑fpm, executing the uploaded code under the www‑data user. This flaw is CWE‑434, an unrestricted upload of files with a dangerous type, allowing an authenticated user with the ROLE_UPLOAD role to run arbitrary PHP code, which compromises confidentiality, integrity, and availability of the system. Based on the description, the attack vector is an authenticated upload by a user with the ROLE_UPLOAD permission.

Affected Systems

All Malcolm releases from cisagov before version 26.06.1 are affected. The vulnerability resides in the file‑upload endpoint POST /server/php/submit.php, with uploaded files stored in /var/www/upload/server/php/files; users granted the granular ROLE_UPLOAD role in RBAC mode can upload files, a role intended only for capture files.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, but the EPSS score of less than 1% indicates a very low current likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. An attacker must authenticate as a user with the ROLE_UPLOAD permission, upload a malicious PHP file, and later trigger its execution with a GET request. The highest risk occurs when RBAC is not hardened and the upload endpoint remains reachable to users with limited permissions.

Generated by OpenCVE AI on October 2, 2026 at 21:55 UTC.

Remediation

Vendor Solution

Malcolm version 26.06.1 addresses this issue. For more information, see  https://github.com/cisagov/Malcolm/pull/1026


OpenCVE Recommended Actions

  • Upgrade to Malcolm 26.06.1 or later to apply the fix that removes the unrestricted upload flaw.
  • If an upgrade is not immediately possible, restrict the file‑upload component by configuring file-upload/php/config.php to include a non‑empty allow‑list that excludes .php files, thereby preventing dangerous uploads.
  • Alternatively, modify the nginx configuration so that requests for .php files in the upload directory are not routed to php‑fpm, treating uploaded files as static content and blocking execution.

Generated by OpenCVE AI on October 2, 2026 at 21:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisagov
Cisagov malcolm
Vendors & Products Cisagov
Cisagov malcolm

Wed, 12 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array by default (`file-upload/php/config.php:16`), so the type check is a no-op and every extension is accepted. The filename sanitizer keeps the `.php` extension intact. Committed files land in `/var/www/upload/server/php/files` (`file-upload/php/config.php:7`), and the component's nginx routes any URL ending in `.php` to php-fpm. An authenticated `GET /server/php/files/<name>.php` then executes the uploaded code as `www-data`. Prior to version 26.06.1, in RBAC mode, the upload endpoint is reachable by the granular `ROLE_UPLOAD` role (`nginx/lua/nginx_auth_helpers.lua:71`), a role intended only for submitting capture files. As a result, a user holding the upload-only role runs arbitrary PHP as `www-data` inside the file-upload container. Version 26.06.1 fixes the issue.
Title Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload component
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-02T20:20:14.228Z

Reserved: 2026-06-17T00:05:03.778Z

Link: CVE-2026-55676

cve-icon Vulnrichment

Updated: 2026-08-12T22:09:15.579Z

cve-icon NVD

Status : Deferred

Published: 2026-08-11T21:17:37.560

Modified: 2026-10-02T21:16:55.597

Link: CVE-2026-55676

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T22:00:24Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type