Cybersecurity and Infrastructure Security Agency Malcolm是Cybersecurity and Infrastructure Security Agency组织的一款网络流量与日志分析平台。 Cybersecurity and Infrastructure Security Agency Malcolm 26.07.0之前版本存在授权问题漏洞,该漏洞源于Nginx OpenResty Lua层中的角色访问控制评估原始未标准化的request_uri,而
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-55676 | 8.8 HIGH | Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload component |
| CVE-2026-63133 | 6.5 MEDIUM | Malcolm has Uncontrolled Resource Consumption in Archive Extraction (Inode-Exhaustion DoS) |
| CVE-2026-63134 | 5.4 MEDIUM | Malcolm's Path Traversal in Archive Extraction Allows Arbitrary Directory Creation |
No comments yet