Description
Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the proxy and the identity provider could impersonate the identity provider and issue forged authentication tokens accepted by the deployment.
Published: 2026-09-11
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Forged authentication tokens from an impersonated identity provider
Action: Upgrade
AI Analysis

Impact

The vulnerability arises because the reverse proxy for the certificate of the identity‑provider service when performing token discovery, introspection, and credential exchange. As a result, a hostile entity controlling traffic between the proxy and the identity‑ authentication tokens that the installation accepts. The primary impact is the ability to obtain unauthorized authentication and potential access to protected resources within the deployment. This flaw is classified as CWE‑295.

Affected Systems

All versions of the Malcolm platform deployed prior to the September 2026 release are affected. The issue exists in the identity‑provider service; users running older Malcolm releases the flaw.

Risk and Exploitability

The CVSS score of 6 indicates a medium severity flaw, and the EPSS score is <1%, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely‑ reverse proxy and the identity‑provider, requiring network‑level control over that channel. This scenario raises the risk posture to medium, contingent on an adversary’s ability to intercept or inject traffic in that pathway.

Generated by OpenCVE AI on September 15, 2026 at 20:53 UTC.

Remediation

Vendor Solution

The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.


OpenCVE Recommended Actions

  • Upgrade Malcolm to the September 2026 release or later to apply the fix for certificate verification.
  • Configure the reverse proxy and identity‑provider connections to enforce server‑certificate validation if the platform allows custom TLS settings.
  • Review network segmentation to‑provider endpoints, reducing the attack surface.

Generated by OpenCVE AI on September 15, 2026 at 20:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Malcolm Reverse Proxy Fails to Verify Identity Provider Certificates

Tue, 15 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Malcolm Reverse Proxy Fails to Verify Identity Provider Certificates

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Identity Provider TLS Certificate Verification Failure Enabling Forged Authentication Tokens

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Title Identity Provider TLS Certificate Verification Failure Enabling Forged Authentication Tokens

Mon, 14 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Unverified TLS Enables Identity Provider Impersonation and Token Forgery

Sun, 13 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisagov
Cisagov malcolm
Vendors & Products Cisagov
Cisagov malcolm

Sun, 13 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unverified TLS Enables Identity Provider Impersonation and Token Forgery

Sun, 13 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Title Server Certificate Verification Failure in Malcolm Reverse Proxy

Sat, 12 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Server Certificate Verification Failure in Malcolm Reverse Proxy

Sat, 12 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unverified TLS in Malcolm Reverse Proxy Allows Forged Authentication Tokens

Sat, 12 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title Unverified TLS in Malcolm Reverse Proxy Allows Forged Authentication Tokens

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the proxy and the identity provider could impersonate the identity provider and issue forged authentication tokens accepted by the deployment.
Weaknesses CWE-295
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-14T13:00:30.656Z

Reserved: 2026-09-11T21:00:09.301Z

Link: CVE-2026-90452

cve-icon Vulnrichment

Updated: 2026-09-14T12:57:24.046Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T22:16:47.473

Modified: 2026-09-18T19:39:09.490

Link: CVE-2026-90452

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:00:17Z

Weaknesses
  • CWE-295

    Improper Certificate Validation