Description
A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes arbitrary script in the context of the affected application and can redirect the user's browser to an arbitrary external site. Successful exploitation could allow an attacker to act with the compromised user's session privileges within the application.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Script execution via cross‑site scripting, allowing an attacker to perform actions with the victim's session privileges
Action: Immediate Patch
AI Analysis

Impact

The vulnerable web interface includes a portion of the request that can be triggered by any network user. An attacker can craft a link containing malicious JavaScript; when an end‑user opens the link inside the Malcolm application, the script executes in the context of the application and can redirect the user's browser to an arbitrary external site. Successful exploitation allows the attacker to act with the compromised user's session rights, potentially leading to further exploitation of the system.

Affected Systems

Instances of the Malcolm platform that release are affected. Versions released before September ; upgrading to the September 2026 or later release resolves the flaw.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate risk. The EPSS score of < 1% and the fact that it is not listed in CISA KEV suggest that widespread exploitation is unlikely. The attack vector is straightforward for an unauthenticated attacker, who only needs to send a crafted link that a user will subsequently open.

Generated by OpenCVE AI on September 15, 2026 at 20:55 UTC.

Remediation

Vendor Solution

The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.


OpenCVE Recommended Actions

  • Update Malcolm to the latest September 2026 or later release.
  • If an immediate upgrade is not possible, ensure that all URL fragments are properly encoded before embedding them in script tags or href attributes and enforce strict input validation.
  • Restrict unauthenticated access to the web interface or implement access controls to reduce exposure.

Generated by OpenCVE AI on September 15, 2026 at 20:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via Unauthenticated URL Reflection in Malcolm

Tue, 15 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Cross‑Site Scripting in Malcolm Web Interface Allows Session‑Based Actions

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Cross‑Site Scripting in Malcolm Web Interface Allows Session‑Based Actions

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Reflected XSS in Malcolm Web Interface Allows Unauthenticated Script Execution

Sun, 13 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisagov
Cisagov malcolm
Vendors & Products Cisagov
Cisagov malcolm

Sun, 13 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Reflected XSS in Malcolm Web Interface Allows Unauthenticated Script Execution

Sun, 13 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title Reflected XSS in Malcolm Web Interface Enables Attacker-Driven Session Abuse

Sat, 12 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Reflected XSS in Malcolm Web Interface Enables Attacker-Driven Session Abuse

Sat, 12 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated XSS Vulnerability Enabling Session‑Based Attacks in Malcolm

Sat, 12 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated XSS Vulnerability Enabling Session‑Based Attacks in Malcolm

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes arbitrary script in the context of the affected application and can redirect the user's browser to an arbitrary external site. Successful exploitation could allow an attacker to act with the compromised user's session privileges within the application.
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-14T13:00:31.277Z

Reserved: 2026-09-11T21:00:07.497Z

Link: CVE-2026-90443

cve-icon Vulnrichment

Updated: 2026-09-14T12:57:33.255Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T22:16:46.247

Modified: 2026-09-18T19:40:31.053

Link: CVE-2026-90443

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:00:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')