Improper Authentication in Malcolm Kiosk Application by CISA
CVE-2026-107337
7.1HIGH
What is CVE-2026-107337?
The Malcolm Kiosk Flask application presents a serious vulnerability through its exposed POST /script_call/ endpoint, which operates without any authentication and utilizes a wildcard CORS setup. This configuration enables an attacker to conduct Cross-Site Request Forgery (CSRF) attacks, potentially prompting the operator's browser to execute arbitrary management commands. Such commands could include destructive actions, like ācontrol.py --wipeā, which eliminates all captured network traffic and forensic logs, or ācontrol.py --stopā, which could incapacitate the security monitoring entirely. These vulnerabilities can significantly hinder the operational integrity of the system.
Affected Version(s)
Malcolm 0 <= 26.07.1
Malcolm 26.08.0
