Malcolm 基于 Nginx 的反向代理服务器在其基于 Lua 的基于角色的访问控制(RBAC)授权层与 Nginx 自身请求路由逻辑之间存在 URL 路径规范化不一致的问题。经过身份验证的用户可以构造特殊格式的请求路径,从而绕过基于角色的访问限制,访问本不应具有权限的管理界面或受角色保护的接口。该漏洞影响所有由 RBAC 授权层保护的受限路径,包括文件上传、PHP 服务器、htadmin 以及身份验证管理接口。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107362 | 7.1 HIGH | Server-Side Request Forgery in Malcolm |
| CVE-2026-107337 | 7.1 HIGH | Cross-Site Request Forgery in Malcolm |
| CVE-2026-107336 | 6.5 MEDIUM | Authentication Bypass by Spoofing in Malcolm |
| CVE-2026-107335 | 6.5 MEDIUM | Improper Handling of Highly Compressed Data in Malcolm |
| CVE-2026-107334 | 5.4 MEDIUM | Incorrect Authorization in Malcolm |
| CVE-2026-107361 | 4.2 MEDIUM | Authentication Bypass Using an Alternate Path or Channel in Malcolm |
No comments yet