Impact
The vulnerability arises when the reverse proxy is configured in a specific authentication mode; it forwards requests for a bundled third‑party administrative interface directly to that interface, bypassing the gateway’s own authentication requirement. This represents a failure to enforce authentication ( this is delegated entirely to that third‑party interface’s own login mechanism. Thus, any authentication weakness in that bundled interface would allow an attacker to compromise the credential store protecting the rest of the deployment.
Affected Systems
Malcolm, the product from CISA, is the only affected product identified by the CNA. The flaw exists in the current versions of Malcolm; the latest release, available from September 2026 onward, contains the fix.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. The EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not listedbased: an attacker who can reach the reverse proxy could send requests that are forwarded directly to the third‑party admin interface. If the attacker compromises the credential store – and therefore all services on the deployment – significant confidentiality and integrity risks result.
OpenCVE Enrichment