Cross-Site Scripting Vulnerability in Web Application by Vendor
CVE-2026-90443

5.3MEDIUM

Key Information:

Vendor

Cisa

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-90443?

A critical cross-site scripting vulnerability exists in the web application's interface due to improper handling of request URLs. The application reflects parts of the request without sufficient encoding, enabling unauthenticated attackers to create malicious links. Once a user clicks on such a link, it executes arbitrary scripts within the context of the user's session. This can result in unauthorized actions on behalf of the user, including redirection to harmful external sites.

Affected Version(s)

Malcolm 0

Malcolm v26.06.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.