Impact
An environment-configuration file that ships with Malcolm contains a fixed, publicly known secret used to sign authentication cookies for a bundled packet-analysis component. If a deployment copies this example file into its active configuration without executing the setup routine that regenerates the default key, an attacker can forge valid authentication cookies, thereby bypassing actions with elevated privileges. This weakness is a classic example of using a predictable secret to sign tokens, as identified by CWE-1392.
Affected Systems
The Malcolm system includes a bundled example environment configuration file that introduces a fixed, publicly known secret for signing authentication cookies in its packet-analysis component. Deployments that have not applied the September 2026 release, or earlier versions that still use the same secret, are at risk if they use the default signing key.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, and the EPSS score is reported as <1%, indicating a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed mass exploitation to date. The attack deployment that does not regenerate the signing key exposes the component to authentication forgery and potential privilege escalation.
OpenCVE Enrichment