CISA Malcolm
Plan PatchCVSS 8.8ICS-CERT ICSA-26-254-01Sep 11, 2026
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Malcolm versions prior to 26.06.0 contain multiple vulnerabilities including reflected cross-site scripting (CWE-79), command injection (CWE-78), path traversal (CWE-22), server-side request forgery (CWE-918), insufficient authentication (CWE-290), authorization flaws (CWE-862, CWE-863), missing certificate validation (CWE-295), and open redirect (CWE-601). These vulnerabilities allow authenticated attackers to execute commands, access sensitive data, manipulate system state, and escalate privileges.
What this means
What could happen
An authenticated attacker could inject commands into Malcolm to execute arbitrary actions on the system, access sensitive configuration and data, bypass security controls, or redirect users to malicious sites. This could compromise the integrity and availability of network traffic analysis and threat intelligence operations.
Who's at risk
Network security operations centers, threat intelligence teams, and SOC analysts who use Malcolm for network traffic analysis and threat detection. Malcolm deployments with direct internet exposure or shared network segments with untrusted systems are at highest risk. Deployments relying on Keycloak for authentication without certificate validation are vulnerable to credential theft via man-in-the-middle attacks.
How it could be exploited
An attacker with valid Malcolm credentials (engineering or analyst account) could exploit multiple input validation flaws to inject commands that execute on the server, traverse the file system to read sensitive files, forge requests to internal services, or manipulate authentication checks. An unauthenticated attacker on the network could exploit server-side request forgery or man-in-the-middle the Keycloak connection if certificate validation is not enabled.
Prerequisites
- Valid Malcolm user credentials (analyst, engineer, or administrative account)
- Network access to the Malcolm web interface (typically port 443)
- For SSRF/MITM attacks: position on network path between Malcolm and its identity provider (Keycloak)
Remotely exploitableRequires authentication (but credential compromise is common)Low complexityMultiple authorization and input validation flawsMissing certificate validation allows credential interceptionAffects security monitoring infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (1)
ProductAffected VersionsFix Status
Malcolm <v26.06.0<v26.06.0Fix available
Remediation & Mitigation
0/4
Do now
0/2HARDENINGAfter updating, explicitly set the KEYCLOAK_SSL_VERIFY configuration variable to enable certificate validation for the identity provider connection
HARDENINGRestrict network access to the Malcolm web interface to authorized analyst and engineering workstations only
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate Malcolm to version 26.06.0 or later (September 2026 or later release)
Long-term hardening
0/1HARDENINGReview and audit Malcolm user accounts; remove or disable inactive credentials and apply principle of least privilege to assigned roles
CVEs (15)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/0e1a4276-8518-4cdd-8563-4644d473bb84Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.