CVE-2026-90446: CWE-918 Server-side request forgery (SSRF) in CISA Malcolm
An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows an authenticated attacker to substitute an arbitrary backend path, causing the application's own elevated service credentials to be used against unintended internal endpoints. This could allow an attacker to enumerate or read internal configuration and administrative data from the backend data store that would otherwise be restricted.
AI Analysis
Technical Summary
The vulnerability exists because an API endpoint in CISA Malcolm accepts user-supplied input and directly uses it in the path of backend requests to the search and analytics data store without restricting or validating the input. This enables an authenticated attacker to manipulate the backend path, causing the application to use its elevated service credentials to access internal endpoints that should be restricted. The attacker could enumerate or read sensitive internal configuration and administrative data from the backend data store.
Potential Impact
An authenticated attacker can leverage this SSRF vulnerability to access internal backend endpoints with elevated service credentials, potentially exposing sensitive configuration and administrative data that should be protected. This could lead to information disclosure within the internal network environment.
Mitigation Recommendations
No official patch or remediation is currently available for this vulnerability. Users should monitor the vendor advisory for updates. In the meantime, restrict access to the affected API endpoint to trusted users only and consider network-level controls to limit backend service access. Avoid exposing the vulnerable API publicly until a fix is released.
CVE-2026-90446: CWE-918 Server-side request forgery (SSRF) in CISA Malcolm
Description
An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows an authenticated attacker to substitute an arbitrary backend path, causing the application's own elevated service credentials to be used against unintended internal endpoints. This could allow an attacker to enumerate or read internal configuration and administrative data from the backend data store that would otherwise be restricted.
CVSS v4.0
Score 5.3medium
Affected software
CISA
Malcolm
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists because an API endpoint in CISA Malcolm accepts user-supplied input and directly uses it in the path of backend requests to the search and analytics data store without restricting or validating the input. This enables an authenticated attacker to manipulate the backend path, causing the application to use its elevated service credentials to access internal endpoints that should be restricted. The attacker could enumerate or read sensitive internal configuration and administrative data from the backend data store.
Potential Impact
An authenticated attacker can leverage this SSRF vulnerability to access internal backend endpoints with elevated service credentials, potentially exposing sensitive configuration and administrative data that should be protected. This could lead to information disclosure within the internal network environment.
Mitigation Recommendations
No official patch or remediation is currently available for this vulnerability. Users should monitor the vendor advisory for updates. In the meantime, restrict access to the affected API endpoint to trusted users only and consider network-level controls to limit backend service access. Avoid exposing the vulnerable API publicly until a fix is released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- icscert
- Date Reserved
- 2026-09-11T21:00:07.497Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa47a7955bf5e2cf581b368
Added to database: 09/11/2026, 22:02:33 UTC
Last enriched: 09/11/2026, 22:17:35 UTC
Last updated: 09/11/2026, 22:23:22 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.