Impact
An example environment‑configuration file for a bundled inventory‑management component ships with a fixed, publicly‑known administrative password. If an installation copies this example file into active configuration without running the setup routine that regenerates credentials, the component’s administrative interface can be accessed by anyone who knows the default value. This flaw is a credential reuse weakness that can give an attacker full administrative control over the component, potentially compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability applies to any Malcolm instance distributed by CISA prior to the September 2026 release that includes the bundled inventory‑management component; users running those earlier versions must check whether they have deployed the example configuration file unchanged.
Risk and Exploitability
The CVSS score of 9.2 indicates critical severity, while the EPSS score of less than 1% shows a low probability of exploitation. The likely attack vector is over the network, as the administrative interface is exposed to anyone who can reach the component’s network endpoint. Exploiting the default administrative credentials would give full control over the inventory‑management component, creating high risk for environments that expose the interface to untrusted networks.
OpenCVE Enrichment