# CISA Malcolm ships 15 flaws, patch urged

Published: 2026-10-01 · Severity: routine · Sectors: energy, technology, infrastructure
Canonical: https://vorant.io/reports/2804be77-ee8e-53c1-bc82-9448a66d00db/cisa-malcolm-ships-15-flaws-patch-urged

> CISA's own Malcolm network-traffic analysis tool has 15 vulnerabilities including unauthenticated XSS, command injection, and auth bypass; update to v26.06.0+.

CISA published an ICS advisory for Malcolm, its open-source network traffic analysis tool used across Energy, Information Technology, and Water/Wastewater sectors worldwide. Versions prior to v26.06.0 contain 15 distinct vulnerabilities spanning unauthenticated reflected XSS/open redirect in the web interface, OS command injection via unsanitized uploaded filenames, path traversal during archive extraction, SSRF through unvalidated backend path interpolation, authentication bypass via a client-controlled routing header, missing authorization on read-only deployment modes allowing record forgery and tag tampering, missing authentication for a bundled admin interface that gates the credential store, a fail-open authorization default for unregistered request handlers, hardcoded default secrets/credentials in example configuration files (session-signing key and an inventory component's admin password), weak password hashing with world-readable permissions, a reverted dependency reintroducing a known-vulnerable HTTP client library, and missing TLS certificate validation between the reverse proxy and the identity provider.

Chained together, several of these flaws could allow an unauthenticated or low-privileged attacker to escalate to administrative control, exfiltrate or tamper with ingested log/session data, pivot into internal networks, or forge authentication tokens. CISA reports no known public exploitation at this time. All issues are fixed in Malcolm's September 2026 release (v26.06.0+); the TLS-verification fix additionally requires administrators to manually set KEYCLOAK_SSL_VERIFY, as it is not enabled by default even after patching.

Defenders running Malcolm should prioritize upgrading immediately, rotate any credentials or secrets that may have been copied from example configuration files without regeneration, verify file permissions on password hash stores, and explicitly enable KEYCLOAK_SSL_VERIFY where the identity provider is not on a fully trusted network segment. Standard ICS guidance applies: minimize internet exposure, segment control system networks from business networks, and use VPNs with awareness of their own risks for remote access.

## Mentioned in this report

- Vulnerabilities: CVE-2026-90443, CVE-2026-90444, CVE-2026-90445, CVE-2026-90446, CVE-2026-90447, CVE-2026-90448, CVE-2026-90449, CVE-2026-90450, CVE-2026-90451, CVE-2026-90452, CVE-2026-90453, CVE-2026-90454, CVE-2026-90455, CVE-2026-90456, CVE-2026-90457

## Detection guidance (public sample)

### Web/Upload Handler Spawning Shell With Metacharacters in Pcap Filename

ATT&CK: T1059

Python/WSGI/web server process spawning a shell whose command line has a pcap/archive filename combined with command-substitution or separator metacharacters, consistent with OS command injection via uploaded filenames (Malcolm-style). Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Web/Upload Handler Spawning Shell With Metacharacters in Pcap Filename
id: 46c7bf0d-7caa-5183-a4a0-7ec6d387eb94
status: experimental
description: Detects a Python/WSGI/web server process spawning a shell whose command
  line contains a capture or archive filename together with command substitution or
  command separators. This is consistent with OS command injection through unsanitized
  uploaded filenames, as in the Malcolm advisory. Applies to Linux hosts or containers
  with process telemetry.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01
tags:
- attack.execution
- attack.t1059
- attack.initial-access
- attack.t1190
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
    - /python
    - /python3
    - /gunicorn
    - /uwsgi
    - /nginx
    - /apache2
    - /httpd
    - /php-fpm
  selection_shell:
    Image|endswith:
    - /sh
    - /bash
    - /dash
  selection_file:
    CommandLine|contains:
    - .pcap
    - .pcapng
    - .zip
    - .tar
  selection_meta:
    CommandLine|contains:
    - $(
    - '`'
    - ;
    - '&&'
    - '||'
  condition: selection_parent and selection_shell and selection_file and selection_meta
falsepositives:
- Legitimate upload-processing scripts that chain commands with ; or && after handling
  a pcap or archive file
- Administrators running pcap processing wrappers from a Python service
level: medium
author: Vorant
```

### Web Application Process Spawning Shell With Download or Reverse Shell Primitives

ATT&CK: T1190

Web server or Python application process spawning a shell that runs curl/wget piped to a shell, netcat, or /dev/tcp redirection, indicating post-exploitation after injection or exploit of a public-facing application. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Web Application Process Spawning Shell With Download or Reverse Shell Primitives
id: 2e504a19-feef-5add-86e2-58d280d04d83
status: experimental
description: Detects web server or Python application processes spawning a shell that
  fetches and executes remote content or opens a reverse shell. Fits post-exploitation
  following command injection in public-facing analysis or admin web interfaces such
  as Malcolm. Applies to Linux hosts or containers with process telemetry.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01
tags:
- attack.initial-access
- attack.t1190
- attack.execution
- attack.t1059
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
    - /python
    - /python3
    - /gunicorn
    - /uwsgi
    - /nginx
    - /apache2
    - /httpd
    - /php-fpm
  selection_shell:
    Image|endswith:
    - /sh
    - /bash
    - /dash
  selection_payload:
    CommandLine|contains:
    - /dev/tcp/
    - bash -i
    - nc -e
    - ncat -e
    - '| sh'
    - '| bash'
    - '|sh'
    - '|bash'
  condition: selection_parent and selection_shell and selection_payload
falsepositives:
- Application health checks or installer scripts that pipe a downloaded script to
  a shell from a Python service
- Containerized deployment tooling that bootstraps components via curl piped to sh
level: high
author: Vorant
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/2804be77-ee8e-53c1-bc82-9448a66d00db/cisa-malcolm-ships-15-flaws-patch-urged.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
