Description
The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered in this table is reachable by any authenticated user regardless of their assigned role, and any newly added handler is fail-open by default until explicitly added to the table.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation via fail‑open role authorization (CWE-863)
Action: Patch
AI Analysis

Impact

A misconfiguration in the role‑authorization lookup causes Malcolm to grant access when a request handler’s name is missing from its role‑requirements table, rather than denying it. The flaw, a CWE‑863 Authorization Bypass, allows any authenticated user to invoke handlers that have not been explicitly registered. Accessing an unregistered handler can expose privileged operations beyond the user’s intended role.

Affected Systems

All Malcolm installations that have not been updated to the September 2026 release or later are impacted. The vulnerability applies to every request handler not explicitly registered, including custom handlers added after deployment.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity, while an EPSS score of < 1 % suggests a low probability of exploitation today. The flaw requires valid authentication to reach the exploit; authenticated users can simply invoke any unregistered handler. No special privileges are required, and the vulnerability is readily exploitable with minimal technical skill.

Generated by OpenCVE AI on September 15, 2026 at 20:53 UTC.

Remediation

Vendor Solution

The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.


OpenCVE Recommended Actions

  • Apply the vendor‑published patch that updates Malcolm to September 2026 or later.
  • Register any custom request handlers in the role‑requirement table to eliminate fail‑open behavior.
  • If the application supports configuration, enforce deny for any request handler not explicitly listed as a temporary workaround.

Generated by OpenCVE AI on September 15, 2026 at 20:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Fail‑Open Role Authorization Leading to Privilege Escalation in Malcolm

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Fail‑Open Role Authorization Leading to Privilege Escalation in Malcolm
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title Fail-Open Role Authorization Enables Unauthorized Access in Malcolm

Mon, 14 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Fail-Open Role Authorization Enables Unauthorized Access in Malcolm

Sun, 13 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisagov
Cisagov malcolm
Vendors & Products Cisagov
Cisagov malcolm

Sun, 13 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Fail‑Open Role Authorization in Malcolm

Sat, 12 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Fail‑Open Role Authorization in Malcolm

Sat, 12 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Fail‑Open Role Authorization Leading to Privilege Escalation in Malcolm

Sat, 12 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title Fail‑Open Role Authorization Leading to Privilege Escalation in Malcolm

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered in this table is reachable by any authenticated user regardless of their assigned role, and any newly added handler is fail-open by default until explicitly added to the table.
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-14T16:22:23.372Z

Reserved: 2026-09-11T21:00:09.301Z

Link: CVE-2026-90450

cve-icon Vulnrichment

Updated: 2026-09-14T16:22:19.778Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T22:16:47.220

Modified: 2026-09-18T19:40:31.053

Link: CVE-2026-90450

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:00:17Z

Weaknesses