SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-91002

MEDIUM · CVSS 5.3 EPSS 0.44% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability exists in the Blacklist Endpoint of the stamparm maltrail up to version 3.0.1, where improper authentication in the _blacklist function can be exploited remotely, potentially allowing unauthorized access. Organizations using this software should prioritize upgrading to version 3.1, which addresses the issue by requiring authentication for access to the endpoint. Immediate action is recommended, as public exploit code is available.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-91002
Severity
MEDIUM
CVSS
5.3
EPSS
0.44%

Original NVD Description

A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of the file core/httpd.py of the component Blacklist Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.1 is able to resolve this issue. This patch is called d95868dff3da4d3bd4f942837a26cb7c73a797ae. It is suggested to upgrade the affected component. The vendor fixed the issue the same day it was reported, in version 3.1, by gating the endpoint on an authenticated session or the new Blacklist_ALLOWLIST option.