---
id: CVE-2026-90444
title: >-
  A file-transfer interface that requires valid credentials accepts
  attacker-controlled filenames without restricting shell metacharacters
summary: >-
  A file-transfer interface that requires valid credentials accepts
  attacker-controlled filenames without restricting shell metacharacters. An
  automated process later constructs and runs a system command using the
  uploaded file's name, all…
severity: high
cvss: 8.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-78
vendor: CISA
product: Malcolm
affected:
  - Malcolm < v26.06.0
published: '2026-09-11'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:40:31.053'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90444'
references:
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
epss: 0.00396
epssPercentile: 0.31209
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-14T12:51:23.616899Z'
cvssSource: cna
ingestedAt: '2026-09-14T15:23:07.429Z'
---

## Overview

A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed and execute arbitrary operating system commands with the privileges of that process. This allows an attacker to read and modify ingested log data, and could provide a foothold for further movement within the internal network.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
