File Upload Exploit in Affected Product by Vendor
CVE-2026-90445

7.1HIGH

Key Information:

Vendor

Cisa

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-90445?

The vulnerability affects an interface that allows file uploads from authenticated users. It improperly handles the extraction of files from uploaded archives, failing to validate that the extracted file paths are confined to the intended destination. Consequently, an authenticated attacker can create a specially crafted archive that directs the extraction process to write files beyond the designated directory. This oversight enables the potential for an attacker to manipulate stored data or alter application configurations, leveraging the privileges of the extraction process.

Affected Version(s)

Malcolm 0

Malcolm v26.06.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.