Impact
A routing rule in Malcolm selects the authentication mechanism based on a client‑supplied request header. This allows an authenticated user who possesses a shared service credential to set the header and bypass the primary role‑based authorization, reaching a path that grants a fixed elevated role. The vulnerability is an instance of improper authorization (CWE‑290) and could let a low‑privileged attacker perform actions reserved for a higher‑privileged role.
Affected Systems
Any Malcolm installation that was released before September 2026 contains the vulnerable routing rule. These deployments are at risk when request headers influence authentication decisions.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score of < 1 % shows a very low but non‑zero likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog. Based on the description, the likely attack path requires an authenticated user who knows the shared service credential to set the client‑supplied request header, causing the request to be routed to an alternate path that assigns an elevated role. This bypass can be used to perform actions normally reserved for higher‑privileged users.
OpenCVE Enrichment