Impact
An API endpoint in Malcolm accepts a user‑supplied path for a backend request to the underlying search and analytics data store without any validation. This is a case of CWE‑918. Because the API requires authentication, an attacker who has valid credentials can craft a request that causes the service to issue a request to any internal path. The application then uses its own elevated service credentials to query that internal endpoint, enabling the attacker to enumerate or read data from the backend data store that would normally be protected.
Affected Systems
The flaw exists in versions of Malcolm released before September 2026; all earlier releases are vulnerable. Deployments that use older releases are at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 5.3 labels the vulnerability as moderate, and the EPSS score of less than 1 % indicates a very low probability of exploitation at this time. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Exploitation requires an authenticated session against the API, so the threat is confined to accounts that are already compromised or have excessive privileges. An attacker could therefore gain inside access to sensitive internal data, but remote unauthenticated exploitation is not possible.
OpenCVE Enrichment