Improper Authentication in Malcolm Kiosk Application by CISA
CVE-2026-107337

7.1HIGH

Key Information:

Vendor

Cisa

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107337?

The Malcolm Kiosk Flask application presents a serious vulnerability through its exposed POST /script_call/ endpoint, which operates without any authentication and utilizes a wildcard CORS setup. This configuration enables an attacker to conduct Cross-Site Request Forgery (CSRF) attacks, potentially prompting the operator's browser to execute arbitrary management commands. Such commands could include destructive actions, like ā€˜control.py --wipe’, which eliminates all captured network traffic and forensic logs, or ā€˜control.py --stop’, which could incapacitate the security monitoring entirely. These vulnerabilities can significantly hinder the operational integrity of the system.

Affected Version(s)

Malcolm 0 <= 26.07.1

Malcolm 26.08.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Seth Grover
.