Impact
A misconfiguration in the role‑authorization lookup causes Malcolm to grant access when a request handler’s name is missing from its role‑requirements table, rather than denying it. The flaw, a CWE‑863 Authorization Bypass, allows any authenticated user to invoke handlers that have not been explicitly registered. Accessing an unregistered handler can expose privileged operations beyond the user’s intended role.
Affected Systems
All Malcolm installations that have not been updated to the September 2026 release or later are impacted. The vulnerability applies to every request handler not explicitly registered, including custom handlers added after deployment.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, while an EPSS score of < 1 % suggests a low probability of exploitation today. The flaw requires valid authentication to reach the exploit; authenticated users can simply invoke any unregistered handler. No special privileges are required, and the vulnerability is readily exploitable with minimal technical skill.
OpenCVE Enrichment