Impact
The vulnerability exists in a deployment mode that restricts write routes by pattern but neglects routes that alter tags on session records. The proxy allows the request method used for those routes, so an authenticated user can add or remove tags on session records. This allows unauthorized manipulation of session tag data, though it does not grant full system control. The weakness is categorized as Missing Authorization.
Affected Systems
The product affected is Malcolm, managed by CISA. It applies to all versions prior to the September 2026 release; any deployment configured for read specific sub‑versions are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of < 1% indicates a very low likelihood that this vulnerability will be exploited. It is not listed in the KEV catalog. Exploitation requires an authenticated user on a read‑only deployment; once authenticated, the attacker can send tag modification requests through the proxied endpoints, simplifying the attack for authenticated users.
OpenCVE Enrichment