Skip to content

Security1 publisher2 min readPublished

Crafted links could run script in users' sessions on CISA Malcolm before v26.06.0

CISA's Malcolm before v26.06.0 lets an attacker with no account run script in an analyst's session through one crafted link. Four other flaws in the same advisory need a login, and CISA's fix for all five is the September 2026 release.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Crafted links could run script in users' sessions on CISA Malcolm before v26.06.0
Generated illustration

What happened

  • One of the authenticated flaws lets a user with valid file-transfer credentials run operating system commands through a crafted upload filename.
  • A low-privileged user who knows a shared service credential can set a request header to skip the role-based check and act with an elevated role.
  • CISA lists Energy, Information Technology, and Water and Wastewater as the sectors using Malcolm, with deployments worldwide.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Anyone who can get a link in front of a logged-in Malcolm user can use the unauthenticated flaw, so login controls on the instance do not stop it.
  • cost Three of the four authenticated flaws reach stored logs, records or configuration, so data on an instance compromised before the update has to be checked before analysts rely on it.
  • contradiction The affected range ends at v26.06.0 but the named fix is the September 2026 release, so a build between the two sits outside both statements.

The flaw is in a web interface that copies part of the request URL into a script context and into a hyperlink attribute without adequate encoding [2]. CISA classes it as CWE-79, cross-site scripting [12]. The attacker writes the link, and a user has to visit it [3]. The same link can also send that user's browser to any external site the attacker chooses [3].

Among the flaws that need a login, the file-transfer bug reaches furthest. Uploaded filenames are not checked for shell metacharacters. An automated process later builds and runs a system command from the name [7]. CISA lists it as CWE-78 [12]. According to the advisory, an attacker can use it to read and modify ingested log data, and it could provide a foothold for further movement within the internal network [8].

The advisory says the XSS lets an attacker act with the compromised user's session privileges inside the application [4]. The file-transfer interface requires valid credentials [7]. If a session taken through the link can reach that interface, or the authenticated upload and API paths, one click from an analyst could end in commands running on the host. The advisory does not report exploitation, name an actor, or present the flaws as a chain [4].

Two more flaws reach the data itself. Archive uploads are extracted without checking that entries stay inside the destination directory, so a crafted archive writes wherever the extraction process can (CWE-22) [9][12]. CISA names fabricated records in stored data and tampered configuration as the results [9]. A separate API endpoint drops a user-supplied value into the path of a backend request to the search and analytics data store (CWE-918) [10][12]. The application then points its own elevated service credentials at internal endpoints, and the attacker can read configuration and administrative data that would otherwise be restricted [10].

What to watch

  • A CISA revision stating whether Malcolm builds from v26.06.0 up to the September 2026 release contain these fixes.
  • Any report that the reflected XSS or the file-transfer command injection has been used against a deployed Malcolm instance.
  • Exploit detail showing whether a session taken through the XSS can reach the file-transfer, archive or API paths.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories