Malcolm 的 Nginx Lua 基于角色的访问控制(RBAC)层通过模式匹配原始的、经过百分比编码的请求 URI,来判断已认证用户是否可以访问受角色限制的路径(例如 /htadmin、/auth、/admin_login、/arkime/api/esadmin、NetBox、上传端点等)。然而,Nginx 本身在选择实际处理请求的 location 块时,使用的是经过百分比解码和规范化的 URI。由于 RBAC 检查从未对输入进行百分比解码,低权限的已认证用户可以使用百分比编码请求仅管理员可访问的路径(例如
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107333 | 8.1 HIGH | Incorrect Authorization in Malcolm |
| CVE-2026-107362 | 7.1 HIGH | Server-Side Request Forgery in Malcolm |
| CVE-2026-107337 | 7.1 HIGH | Cross-Site Request Forgery in Malcolm |
| CVE-2026-107336 | 6.5 MEDIUM | Authentication Bypass by Spoofing in Malcolm |
| CVE-2026-107335 | 6.5 MEDIUM | Improper Handling of Highly Compressed Data in Malcolm |
| CVE-2026-107361 | 4.2 MEDIUM | Authentication Bypass Using an Alternate Path or Channel in Malcolm |
No comments yet