File Upload Handler Vulnerability in Affected Web Application
CVE-2026-90453
5.1MEDIUM
What is CVE-2026-90453?
A serious issue exists in the file-upload handler of the affected web application, allowing an authenticated attacker to exploit the request's Referer header. If successfully executed, this vulnerability can redirect a different user's browser to an external, potentially malicious destination after completing an upload process. This poses a significant risk to the security of users interacting with the application, as it bypasses the validation of the URL against the application's origin.
Affected Version(s)
Malcolm 0
Malcolm v26.06.0
