Authentication Bypass Vulnerability in Affected Product by Vendor
CVE-2026-90447

7.1HIGH

Key Information:

Vendor

Cisa

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-90447?

This vulnerability enables an authenticated user with a shared service credential to manipulate a request header, allowing the user to bypass the standard role-based authorization checks. By doing so, the attacker can gain access to elevated privileges and perform actions that should be restricted to higher-privileged users. The attack leverages the improper routing of requests based on client-controlled input, creating a critical security concern for the affected product.

Affected Version(s)

Malcolm 0

Malcolm v26.06.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.