🔐 CVE Alert

CVE-2026-107336

MEDIUM 6.5

Authentication Bypass by Spoofing in Malcolm

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Malcolm's front nginx reverse proxy defines a "Dashboards → Arkime shortcut" location using a case-insensitive regex matcher but a case-sensitive rewrite. A request whose path segment is not exact-lowercase (for example /IDDASH2ARK/...) enters the location (the matcher fires) but evades the rewrite (no redirect is issued), so nginx falls through to the location's proxy_pass to the Arkime backend. That location is the one proxied location in the shipped config that does not include the per-location authentication file, so the request reaches Arkime unauthenticated. The same location also forwards a client-supplied X-Forwarded-User header un-overwritten, and Arkime is configured to trust X-Forwarded-User as the authenticated username — so an unauthenticated network caller can reach the Arkime backend while supplying a forged, auto-provisioned identity.

CWE CWE-290 CWE-441 CWE-863
Vendor cisa
Product malcolm
Published Oct 8, 2026
Last Updated Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for cisa malcolm

Be the first to know when new medium vulnerabilities affecting cisa malcolm are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

CISA / Malcolm
0 ≤ 26.07.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/cisagov/Malcolm/security/advisories/GHSA-7j32-cf27-cp6h github.com: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-280-01.json

Credits

Seth Grover