CVE-2026-107337
Received Received - Intake

Malcolm Kiosk Flask CSRF Lets Attackers Wipe Data

Vulnerability report for CVE-2026-107337, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: ICS-CERT

Description

The Malcolm kiosk Flask application exposes a POST /script_call/<script> endpoint with zero authentication and wildcard CORS (CORS(app)). An attacker can force the operator's browser to execute arbitrary management commands via CSRF, including control.py --wipe which permanently deletes all captured network traffic and forensic logs, or control.py --stop which blinds the security monitoring.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
CISA Malcolm 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Malcolm kiosk Flask application. It has an endpoint POST /script_call/<script> that requires no authentication and allows wildcard CORS. An attacker can trick a user's browser into sending requests to this endpoint via CSRF, executing arbitrary management commands like deleting forensic logs or stopping monitoring.

Detection Guidance

Check for unauthorized POST requests to /script_call/<script> endpoints in Malcolm kiosk logs. Monitor network traffic for suspicious CSRF attempts targeting control.py commands like --wipe or --stop. Inspect browser console logs for wildcard CORS misconfigurations.

Impact Analysis

An attacker could exploit this to delete all captured network traffic and forensic logs permanently using control.py --wipe. They could also stop monitoring with control.py --stop, disabling security visibility. This could blind security teams to ongoing or past intrusions.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by allowing deletion of forensic logs and disabling monitoring. GDPR requires data breach logs for 72 hours; HIPAA mandates audit log retention. Loss of logs or monitoring could result in regulatory penalties or fines.

Mitigation Strategies

Disable the exposed /script_call/ endpoint immediately. Remove wildcard CORS settings and implement strict authentication for all management endpoints. Block external access to the Flask application if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107337. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart