Impact
The vulnerability stems from a deployment mode that was intended to expose only read access to stored data, yet the API routes were implemented without restricting which request methods are permitted. One exposed route accepts requests that create or overwrite a stored record, allowing an identifier. The operation is backend credentials, effectively granting the attacker elevated privileges. This flaw enables an authenticated user on a deployment that is meant to be read‑only to forge or replace records that should be immutable, thereby compromising data integrity and representing a missing authorization flaw (CWE-862).
Affected Systems
All Malcolm instances configured in read‑only mode and running any version before the September 2026 release are believed to be affected. The vendor does not provide a specific version.
Risk and Exploitability
The CVSS score of 7.1 indicates significant risk to data integrity. The EPSS score of < 1% suggests a low yet non‑zero likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires an authenticated user with legitimate credentials in a read‑only installation; the attacker targets the exposed write route to create or overwrite records. As a result, older versions running in read‑only mode may be vulnerable and could be exploited by users who obtain valid credentials.
OpenCVE Enrichment