Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107334— Incorrect Authorization in Malcolm

Quick assessment

Affected
CISA Malcolm
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Malcolm 的 Nginx Lua 基于角色的访问控制(RBAC)层通过模式匹配原始的、经过百分比编码的请求 URI,来判断已认证用户是否可以访问受角色限制的路径(例如 /htadmin、/auth、/admin_login、/arkime/api/esadmin、NetBox、上传端点等)。然而,Nginx 本身在选择实际处理请求的 location 块时,使用的是经过百分比解码和规范化的 URI。由于 RBAC 检查从未对输入进行百分比解码,低权限的已认证用户可以使用百分比编码请求仅管理员可访问的路径(例如

CVSS 5.4 · Medium

Affected Version Matrix 2

VendorProduct Version RangeStatus
CISA Malcolm ≤ 26.07.1 affected
26.08.0 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107334

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Incorrect Authorization in Malcolm
Source: CVE Program / CVE List V5
Vulnerability Description
Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /auth, /admin_login, /arkime/api/esadmin, NetBox, upload endpoints) by pattern-matching the raw, percent-encoded request URI. Nginx itself, however, selects which location block actually serves the request using the percent-decoded, normalized URI. Because the RBAC check never percent-decodes its input, an authenticated low-privilege user can request an admin-only path using percent-encoding (e.g. /%68tadmin.php) and have nginx route it to the restricted location while the Lua RBAC gate evaluating the un-decoded raw string finds no matching restriction and grants access.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
CISA Malcolm 0 ~ 26.07.1 -

II. Public POCs for CVE-2026-107334

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107334

请登录查看更多情报信息。

Other References for CVE-2026-107334 (2)

Same Patch Batch · CISA · 2026-10-08 · 7 CVEs total

CVE-2026-107333 8.1 HIGH Incorrect Authorization in Malcolm
CVE-2026-107362 7.1 HIGH Server-Side Request Forgery in Malcolm
CVE-2026-107337 7.1 HIGH Cross-Site Request Forgery in Malcolm
CVE-2026-107336 6.5 MEDIUM Authentication Bypass by Spoofing in Malcolm
CVE-2026-107335 6.5 MEDIUM Improper Handling of Highly Compressed Data in Malcolm
CVE-2026-107361 4.2 MEDIUM Authentication Bypass Using an Alternate Path or Channel in Malcolm

IV. Related Vulnerabilities

V. Comments for CVE-2026-107334

No comments yet


Leave a comment