File Upload Handler Vulnerability in Affected Web Application
CVE-2026-90453

5.1MEDIUM

Key Information:

Vendor

Cisa

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-90453?

A serious issue exists in the file-upload handler of the affected web application, allowing an authenticated attacker to exploit the request's Referer header. If successfully executed, this vulnerability can redirect a different user's browser to an external, potentially malicious destination after completing an upload process. This poses a significant risk to the security of users interacting with the application, as it bypasses the validation of the URL against the application's origin.

Affected Version(s)

Malcolm 0

Malcolm v26.06.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.