Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 12 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized Write via Read‑Only Deployment Mode in Malcolm |
Sat, 12 Sep 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized Write via Read‑Only Deployment Mode in Malcolm |
Fri, 11 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route accepts a request that creates or overwrites a stored record, including an attacker-chosen identifier, using the application's own elevated backend credentials. This allows an authenticated user on a deployment intended to be read-only to forge or overwrite stored records that should not be modifiable in that deployment mode. | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-09-11T21:49:12.225Z
Reserved: 2026-09-11T21:00:09.300Z
Link: CVE-2026-90448
No data.
Status : Received
Published: 2026-09-11T22:16:46.950
Modified: 2026-09-11T22:16:46.950
Link: CVE-2026-90448
No data.
OpenCVE Enrichment
Updated: 2026-09-12T14:45:07Z
-
CWE-862
Missing Authorization