API Endpoint Vulnerability in Search and Analytics Software by Vendor
CVE-2026-90446
5.3MEDIUM
What is CVE-2026-90446?
An application programming interface (API) endpoint is susceptible to manipulation as it directly interpolates user-supplied values into the path of backend requests. This oversight allows an authenticated attacker to insert arbitrary paths, potentially compromising the application by leveraging its own elevated service credentials against unintended internal endpoints. Such an exploitation can result in unauthorized access to enumeration and retrieval of sensitive configuration and administrative data from the backend data store that should remain protected.
Affected Version(s)
Malcolm 0
Malcolm v26.06.0
