Description
A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This allows an authenticated attacker to craft a request that causes another user's browser to be redirected to an arbitrary external destination after completing an upload.
Published: 2026-09-11
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Redirection of authenticated users to arbitrary external sites
Action: Apply Patch
AI Analysis

Impact

Maler header directly into a redirect response without verifying that the value originates from the same domain. This insecure practice enables an authenticated attacker to craft a file‑upload request that, after the upload completes, forces the victim’s browser to navigate to an attacker‑controlled external site, representing an open redirect flaw (CWE‑601). The vulnerability does not provide direct code execution or privilege escalation; its primary effect is to move the user’s session to a potentially malicious destination.

Affected Systems

All Malcolm installations in use by CISA that were deployed prior to the release of the September 2026 update are vulnerable. The September 2026 version removes the unsafe redirect logic, so any older installation remains exposed.

Risk and Exploitability

The CVSS score of 5.1 classifies the flaw as moderate. The EPSS score of < 1 % indicates a very low likelihood that the flaw will be exploited in the wild, and the vulnerability is not yet listed in CISA’s KEV catalog. Exploitation requires an authenticated user capable of sending a request with a contrived Referer header to the upload endpoint; once triggered, it redirects the victim’s browser to the attacker’s specified URL.

Generated by OpenCVE AI on September 15, 2026 at 20:28 UTC.

Remediation

Vendor Solution

The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.


OpenCVE Recommended Actions

  • Upgrade Malcolm to the September 2026 release or newer, which removes the insecure redirect logic.
  • If an upgrade cannot be performed immediately, modify the upload handler to validate that the Referer header starts with the application’s own domain or eliminate the redirect entirely.
  • Deploy web‑application firewall rules that block external redirects originating from authenticated upload endpoints to provide a defensive fallback.

Generated by OpenCVE AI on September 15, 2026 at 20:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Open Redirect via Unvalidated Referer in Malcolm File‑Upload

Tue, 15 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Authenticated Open Redirect via File Upload Referer Header

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Authenticated Open Redirect via File Upload Referer Header

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title Authenticated Open Redirect via Constructed Referer Header

Mon, 14 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Authenticated Open Redirect via Constructed Referer Header

Sun, 13 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisagov
Cisagov malcolm
Vendors & Products Cisagov
Cisagov malcolm

Sun, 13 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Title Open Redirect via Referer Header after File Upload in Malcolm

Sat, 12 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Open Redirect via Referer Header after File Upload in Malcolm

Sat, 12 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Authenticated Open Redirect in Malcolm File‑Upload Handler

Sat, 12 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title Authenticated Open Redirect in Malcolm File‑Upload Handler

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This allows an authenticated attacker to craft a request that causes another user's browser to be redirected to an arbitrary external destination after completing an upload.
Weaknesses CWE-601
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-14T13:00:30.500Z

Reserved: 2026-09-11T21:00:09.301Z

Link: CVE-2026-90453

cve-icon Vulnrichment

Updated: 2026-09-14T12:57:21.701Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T22:16:47.630

Modified: 2026-09-18T19:40:31.053

Link: CVE-2026-90453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:30:10Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')