Description
A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service credential can set this header to route around the primary role-based authorization check and reach the alternate path's fixed, elevated role instead. This allows a low-privileged authenticated attacker who knows the shared credential to perform actions reserved for a higher-privileged role.
Published: 2026-09-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Now
AI Analysis

Impact

A routing rule in Malcolm selects the authentication mechanism based on a client‑supplied request header. This allows an authenticated user who possesses a shared service credential to set the header and bypass the primary role‑based authorization, reaching a path that grants a fixed elevated role. The vulnerability is an instance of improper authorization (CWE‑290) and could let a low‑privileged attacker perform actions reserved for a higher‑privileged role.

Affected Systems

Any Malcolm installation that was released before September 2026 contains the vulnerable routing rule. These deployments are at risk when request headers influence authentication decisions.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity. The EPSS score of < 1 % shows a very low but non‑zero likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog. Based on the description, the likely attack path requires an authenticated user who knows the shared service credential to set the client‑supplied request header, causing the request to be routed to an alternate path that assigns an elevated role. This bypass can be used to perform actions normally reserved for higher‑privileged users.

Generated by OpenCVE AI on September 15, 2026 at 21:41 UTC.

Remediation

Vendor Solution

The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.


OpenCVE Recommended Actions

  • Apply the latest Malcolm release (September 2026 or newer) to eliminate the vulnerable header‑based routing.
  • Replace the shared service credential with distinct credentials for each role to prevent bypass even if a credential is compromised.
  • Review the authentication implementation to confirm that role determination does not rely on untrusted request headers and enforce server‑side checks.

Generated by OpenCVE AI on September 15, 2026 at 21:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Header-Based Authentication Bypass Grants Elevated Role

Tue, 15 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Header-Based Authentication Bypass Grants Elevated Role

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Header‑based routing permits privilege escalation by circumventing role‑based authorization
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Header‑based routing permits privilege escalation by circumventing role‑based authorization

Mon, 14 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Header‑Based Authentication Bypass in Malcolm

Sun, 13 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisagov
Cisagov malcolm
Vendors & Products Cisagov
Cisagov malcolm

Sun, 13 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Header‑Based Authentication Bypass in Malcolm

Sun, 13 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title Client‑Supplied Header Bypasses Role‑Based Authorization in Malcolm

Sat, 12 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Client‑Supplied Header Bypasses Role‑Based Authorization in Malcolm

Sat, 12 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Routing Header Manipulation Allows Privilege Escalation in Malcolm

Sat, 12 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title Routing Header Manipulation Allows Privilege Escalation in Malcolm

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service credential can set this header to route around the primary role-based authorization check and reach the alternate path's fixed, elevated role instead. This allows a low-privileged authenticated attacker who knows the shared credential to perform actions reserved for a higher-privileged role.
Weaknesses CWE-290
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-14T16:14:13.574Z

Reserved: 2026-09-11T21:00:07.497Z

Link: CVE-2026-90447

cve-icon Vulnrichment

Updated: 2026-09-14T16:14:09.736Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T22:16:46.797

Modified: 2026-09-18T19:40:31.053

Link: CVE-2026-90447

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:45:17Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing