API Endpoint Vulnerability in Search and Analytics Software by Vendor
CVE-2026-90446

5.3MEDIUM

Key Information:

Vendor

Cisa

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-90446?

An application programming interface (API) endpoint is susceptible to manipulation as it directly interpolates user-supplied values into the path of backend requests. This oversight allows an authenticated attacker to insert arbitrary paths, potentially compromising the application by leveraging its own elevated service credentials against unintended internal endpoints. Such an exploitation can result in unauthorized access to enumeration and retrieval of sensitive configuration and administrative data from the backend data store that should remain protected.

Affected Version(s)

Malcolm 0

Malcolm v26.06.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.