Authentication Bypass Vulnerability in Affected Product by Vendor
CVE-2026-90447
7.1HIGH
What is CVE-2026-90447?
This vulnerability enables an authenticated user with a shared service credential to manipulate a request header, allowing the user to bypass the standard role-based authorization checks. By doing so, the attacker can gain access to elevated privileges and perform actions that should be restricted to higher-privileged users. The attack leverages the improper routing of requests based on client-controlled input, creating a critical security concern for the affected product.
Affected Version(s)
Malcolm 0
Malcolm v26.06.0
