Impact
A file‑transfer endpoint that requires authentication lets an attacker upload a file with a filename that includes shell metacharacters. Later a system command is built using this filename and executed. The flaw allows an authenticated attacker to embed and run arbitrary operating system commands with the privileges of the service process, giving the attacker the ability to read or modify ingested log data and serve as a foothold for lateral movement.
Affected Systems
Malcolm instances using versions published before September 2026 are vulnerable. Versions released in September 2026 or later incorporate the fix and are not affected.
Risk and Exploitability
The CVSS score of 8.7 marks this flaw as high severity, while the EPSS score of < 1 % indicates a very low but non‑zero chance of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated remote access to the file‑transfer interface, after which arbitrary OS commands can be executed with the process’s privileges.
OpenCVE Enrichment