VYPR
advisoryPublished Oct 1, 2026· 1 source

CISA Flags Multiple Critical Vulnerabilities in CISA Malcolm

CISA has issued an advisory detailing several critical vulnerabilities in CISA Malcolm versions prior to v26.06.0, including cross-site scripting, OS command injection, and path traversal flaws.

The Cybersecurity and Infrastructure Security Agency (CISA) has released a significant advisory highlighting multiple vulnerabilities affecting CISA Malcolm, an industrial control system (ICS) software. The identified flaws, present in versions prior to v26.06.0, pose substantial risks to critical infrastructure sectors including energy, information technology, and water and wastewater systems worldwide.

One of the most critical vulnerabilities, CVE-2026-90443, is an improper neutralization of input during web page generation, commonly known as cross-site scripting (XSS). This flaw allows unauthenticated attackers to craft malicious links that, when visited by a user, can execute arbitrary scripts within the application's context. Furthermore, the vulnerability enables open redirects, allowing attackers to redirect users' browsers to untrusted external sites. Successful exploitation could grant attackers the privileges of the compromised user's session.

Another severe vulnerability, CVE-2026-90444, involves OS command injection. This flaw resides in a file-transfer interface that accepts attacker-controlled filenames without proper sanitization. When these filenames are used to construct system commands, an authenticated attacker can embed and execute arbitrary operating system commands with the privileges of the affected process. This could lead to the modification of ingested log data and provide a foothold for lateral movement within the network.

CVE-2026-90445 addresses a path traversal vulnerability within an interface that handles file uploads from authenticated users. The software extracts archive contents without validating the extracted file paths, allowing attackers to craft archives that traverse outside the intended destination directory. This enables the extraction process to write files to arbitrary locations, potentially overwriting critical system files or injecting malicious content.

Additionally, CVE-2026-90446, a server-side request forgery (SSRF) vulnerability, exists in an API endpoint that interpolates user-supplied values directly into backend requests without proper validation. This allows authenticated attackers to manipulate backend requests, potentially accessing internal configuration or administrative data from the search and analytics data store using the application's elevated service credentials.

CISA has assigned a CVSS v3.1 base score of 8.8 HIGH to the OS command injection vulnerability (CVE-2026-90444), indicating a significant risk. Other vulnerabilities range from medium to high severity, underscoring the broad impact of these issues.

CISA strongly advises affected users to update their instances of CISA Malcolm to the latest version, v26.06.0 or later, which addresses these vulnerabilities. The agency emphasizes the importance of timely patching to mitigate the risks associated with these critical flaws and protect industrial control systems from potential compromise.

Synthesized by Vypr AI