Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 11 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed and execute arbitrary operating system commands with the privileges of that process. This allows an attacker to read and modify ingested log data, and could provide a foothold for further movement within the internal network. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-09-11T21:46:56.442Z
Reserved: 2026-09-11T21:00:07.497Z
Link: CVE-2026-90444
No data.
Status : Received
Published: 2026-09-11T22:16:46.390
Modified: 2026-09-11T22:16:46.390
Link: CVE-2026-90444
No data.
OpenCVE Enrichment
No data.
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')