Impact
A weak, fast hashing and the hash file is world‑readable. Because the stored hash can be read by any local user or from a backup, an attacker can obtain the hash and perform offline attacks to recover the plaintext password. Once the password is recovered, it can be used on all authentication paths that accept it, giving the attacker full administrative control. This weakness falls under CWE‑916, an information‑exposure flaw that enables credential theft.
Affected Systems
Malcolm, a product developed by the Cybersecurity and Infrastructure Security Agency (CISA), is affected. The advisory does not specify version numbers, but states that the latest release from September 2026 or later fixes the issue. Any deployment of Malcolm older than the September 2026 release may suffer from weak hashing and insecure file permissions.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity flaw. The EPSS score of < 1% suggests a very low but nonzero probability of exploitation, although local read access to the credential file is required to benefit. Because the required access is local, the vulnerability can be abused by any local user or attacker who gains local foothold, even from a configuration backup. The flaw is not currently listed in the CISA KEV catalog, indicating no publicly documented exploits, but the ease of local exploitation warrants prompt remediation.
OpenCVE Enrichment