Cross-Site Scripting Vulnerability in Web Application by Vendor
CVE-2026-90443
5.3MEDIUM
What is CVE-2026-90443?
A critical cross-site scripting vulnerability exists in the web application's interface due to improper handling of request URLs. The application reflects parts of the request without sufficient encoding, enabling unauthenticated attackers to create malicious links. Once a user clicks on such a link, it executes arbitrary scripts within the context of the user's session. This can result in unauthorized actions on behalf of the user, including redirection to harmful external sites.
Affected Version(s)
Malcolm 0
Malcolm v26.06.0
