Impact
The vulnerability arises because the reverse proxy for the certificate of the identity‑provider service when performing token discovery, introspection, and credential exchange. As a result, a hostile entity controlling traffic between the proxy and the identity‑ authentication tokens that the installation accepts. The primary impact is the ability to obtain unauthorized authentication and potential access to protected resources within the deployment. This flaw is classified as CWE‑295.
Affected Systems
All versions of the Malcolm platform deployed prior to the September 2026 release are affected. The issue exists in the identity‑provider service; users running older Malcolm releases the flaw.
Risk and Exploitability
The CVSS score of 6 indicates a medium severity flaw, and the EPSS score is <1%, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely‑ reverse proxy and the identity‑provider, requiring network‑level control over that channel. This scenario raises the risk posture to medium, contingent on an adversary’s ability to intercept or inject traffic in that pathway.
OpenCVE Enrichment