Missing Authentication in Stamparm Maltrail Blacklist Endpoint
CVE-2026-91002
Key Information:
Badges
What is CVE-2026-91002?
A vulnerability has been detected in Stamparm Maltrail prior to version 3.1, specifically in the Blacklist Endpoint's _blacklist function located in core/httpd.py. This security flaw permits unauthorized users to manipulate the endpoint, leading to missed authentication checks. An attacker could exploit this vulnerability remotely, and public exploits are accessible. Immediate upgrading to version 3.1 is recommended, as it addresses the issue by requiring an authenticated session or by utilizing the new Blacklist_ALLOWLIST option, implementing vital security controls.
Affected Version(s)
maltrail 3.0.0
maltrail 3.0.1
maltrail 3.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
