Description
A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route accepts a request that creates or overwrites a stored record, including an attacker-chosen identifier, using the application's own elevated backend credentials. This allows an authenticated user on a deployment intended to be read-only to forge or overwrite stored records that should not be modifiable in that deployment mode.
Published: 2026-09-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Record Modification
Action: Immediate Patch
AI Analysis

Impact

The vulnerability stems from a deployment mode that was intended to expose only read access to stored data, yet the API routes were implemented without restricting which request methods are permitted. One exposed route accepts requests that create or overwrite a stored record, allowing an identifier. The operation is backend credentials, effectively granting the attacker elevated privileges. This flaw enables an authenticated user on a deployment that is meant to be read‑only to forge or replace records that should be immutable, thereby compromising data integrity and representing a missing authorization flaw (CWE-862).

Affected Systems

All Malcolm instances configured in read‑only mode and running any version before the September 2026 release are believed to be affected. The vendor does not provide a specific version.

Risk and Exploitability

The CVSS score of 7.1 indicates significant risk to data integrity. The EPSS score of < 1% suggests a low yet non‑zero likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires an authenticated user with legitimate credentials in a read‑only installation; the attacker targets the exposed write route to create or overwrite records. As a result, older versions running in read‑only mode may be vulnerable and could be exploited by users who obtain valid credentials.

Generated by OpenCVE AI on September 15, 2026 at 20:54 UTC.

Remediation

Vendor Solution

The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.


OpenCVE Recommended Actions

  • Update Malcolm to the latest version (September 2026 or later) to apply the vendor fix.
  • Ensure API endpoints in read‑only deployments accept only GET methods and reject POST, PUT, or DELETE requests.
  • Implement strict authorization controls and eliminate the use of elevated backend credentials for public API endpoints to address the missing authorization flaw (CWE-862).
  • Conduct a review of role‑based access controls for read‑only deployments to ensure only authorized users can authenticate.
  • Monitor logs for anomalous write attempts on read‑only systems.

Generated by OpenCVE AI on September 15, 2026 at 20:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Authorized Request Method Misconfiguration Allows Record Overwrite in Read‑Only Mode

Tue, 15 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Authorized Request Method Misconfiguration Allows Record Overwrite in Read‑Only Mode

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Read-Only Mode Allows Authenticated Record Modification
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Title Read-Only Mode Allows Authenticated Record Modification

Mon, 14 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Title Read‑Only Mode Allows Authenticated Record Overwrite in Malcolm

Sun, 13 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisagov
Cisagov malcolm
Vendors & Products Cisagov
Cisagov malcolm

Sun, 13 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Read‑Only Mode Allows Authenticated Record Overwrite in Malcolm

Sun, 13 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Read‑Only Mode Exposes Write Routes Allowing Unauthorized Record Modification

Sat, 12 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Read‑Only Mode Exposes Write Routes Allowing Unauthorized Record Modification

Sat, 12 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Write via Read‑Only Deployment Mode in Malcolm

Sat, 12 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Write via Read‑Only Deployment Mode in Malcolm

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route accepts a request that creates or overwrites a stored record, including an attacker-chosen identifier, using the application's own elevated backend credentials. This allows an authenticated user on a deployment intended to be read-only to forge or overwrite stored records that should not be modifiable in that deployment mode.
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-14T16:12:55.743Z

Reserved: 2026-09-11T21:00:09.300Z

Link: CVE-2026-90448

cve-icon Vulnrichment

Updated: 2026-09-14T16:12:50.482Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T22:16:46.950

Modified: 2026-09-18T19:39:09.490

Link: CVE-2026-90448

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:00:17Z

Weaknesses