PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-55676 cisagov CVE debrief

CVE-2026-55676 debrief based on CVE Program and NVD records. The vulnerability is in Malcolm's file-upload component, allowing arbitrary PHP execution as www-data due to an empty allow-list for file types and a filename sanitizer that keeps the .php extension intact. Users with the ROLE_UPLOAD role are affected. The issue is fixed in version 26.06.1. A detailed review of the CVE Program and NVD records indicates that the vulnerability has a high severity score of 8.8. The vulnerability allows an authenticated user to execute arbitrary PHP code as www-data inside the file-upload container. This could lead to potential code execution and data tampering. The CVE record was published

Vendor
cisagov
Product
Malcolm
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-09-09
Advisory published
2026-08-11
Advisory updated
2026-09-09

Who should care

Users of Malcolm network traffic analysis tool suite, particularly those with the ROLE_UPLOAD role, should assess exposure and apply version 26.06.1 or later. The vulnerability allows an authenticated user to execute arbitrary PHP code as www-data inside the file-upload container, potentially leading to code execution and data tampering. Users should review and apply the patch, restrict access to the file-upload component, and monitor for suspicious

Why it matters

CVE-2026-55676 is a high severity vulnerability in Malcolm's file-upload component, allowing arbitrary PHP execution as www-data. Users with the ROLE_UPLOAD role are affected. The issue is fixed in version 26.06.1.

  • Arbitrary PHP execution as www-data in the file-upload container
  • Potential for code execution and data tampering
  • Need for version 26.06.1 or later for fix
  • Verification of ROLE_UPLOAD role restrictions required

Technical summary

The file-upload component in Malcolm network traffic analysis tool suite has a vulnerability allowing arbitrary PHP execution as www-data due to an empty allow-list for file types and a filename sanitizer that keeps the .php extension intact. The vulnerability has a high severity score of 8.8 and is fixed in version 26.06.1. An authenticated user can execute arbitrary PHP code as www-data inside the file-upload container, potentially leading to code execution and data tampering. The CVE Program and NVD records provide

Defensive priority

High priority for users of Malcolm network traffic analysis tool suite

Recommended defensive actions

  • Review and apply version 26.06.1 or later for Malcolm
  • Restrict access to the file-upload component
  • Monitor for suspicious activity in the file-upload container
  • Verify ROLE_UPLOAD role restrictions
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets

Evidence notes

Evidence from CVE Program and NVD records indicates a vulnerability in Malcolm's file-upload component, allowing arbitrary PHP execution as www-data. The issue is fixed in version 26.06.1. The CVE Program and NVD records provide details on the vulnerability, including its severity score of 8.8 and the affected product versions. The vulnerability is caused by an empty allow-list for file types and a filename sanitizer that keeps the .php extension intact. This allows an authenticated user to execute arbitrary PHP code as www-data

Sources and references

Verified primary and authoritative sources

  • CVE-2026-55676 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-55676

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-55676 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-55676

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.