PatchSiren cyber security CVE debrief
CVE-2026-55676 cisagov CVE debrief
CVE-2026-55676 debrief based on CVE Program and NVD records. The vulnerability is in Malcolm's file-upload component, allowing arbitrary PHP execution as www-data due to an empty allow-list for file types and a filename sanitizer that keeps the .php extension intact. Users with the ROLE_UPLOAD role are affected. The issue is fixed in version 26.06.1. A detailed review of the CVE Program and NVD records indicates that the vulnerability has a high severity score of 8.8. The vulnerability allows an authenticated user to execute arbitrary PHP code as www-data inside the file-upload container. This could lead to potential code execution and data tampering. The CVE record was published
- Vendor
- cisagov
- Product
- Malcolm
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-09-09
Who should care
Users of Malcolm network traffic analysis tool suite, particularly those with the ROLE_UPLOAD role, should assess exposure and apply version 26.06.1 or later. The vulnerability allows an authenticated user to execute arbitrary PHP code as www-data inside the file-upload container, potentially leading to code execution and data tampering. Users should review and apply the patch, restrict access to the file-upload component, and monitor for suspicious
Why it matters
CVE-2026-55676 is a high severity vulnerability in Malcolm's file-upload component, allowing arbitrary PHP execution as www-data. Users with the ROLE_UPLOAD role are affected. The issue is fixed in version 26.06.1.
- Arbitrary PHP execution as www-data in the file-upload container
- Potential for code execution and data tampering
- Need for version 26.06.1 or later for fix
- Verification of ROLE_UPLOAD role restrictions required
Technical summary
The file-upload component in Malcolm network traffic analysis tool suite has a vulnerability allowing arbitrary PHP execution as www-data due to an empty allow-list for file types and a filename sanitizer that keeps the .php extension intact. The vulnerability has a high severity score of 8.8 and is fixed in version 26.06.1. An authenticated user can execute arbitrary PHP code as www-data inside the file-upload container, potentially leading to code execution and data tampering. The CVE Program and NVD records provide
Defensive priority
High priority for users of Malcolm network traffic analysis tool suite
Recommended defensive actions
- Review and apply version 26.06.1 or later for Malcolm
- Restrict access to the file-upload component
- Monitor for suspicious activity in the file-upload container
- Verify ROLE_UPLOAD role restrictions
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
Evidence notes
Evidence from CVE Program and NVD records indicates a vulnerability in Malcolm's file-upload component, allowing arbitrary PHP execution as www-data. The issue is fixed in version 26.06.1. The CVE Program and NVD records provide details on the vulnerability, including its severity score of 8.8 and the affected product versions. The vulnerability is caused by an empty allow-list for file types and a filename sanitizer that keeps the .php extension intact. This allows an authenticated user to execute arbitrary PHP code as www-data
Sources and references
Verified primary and authoritative sources
-
CVE-2026-55676 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-55676
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-55676 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-55676
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/cisagov/Malcolm/releases/tag/v26.06.1
-
Source reference
Unverified legacy reference
URL: https://github.com/cisagov/Malcolm/security/advisories/GHSA-8cvp-m7pg-qrp7
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.