CVE-2026-107333: Incorrect Authorization in Malcolm
Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authorization layer and nginx's own request routing logic. An authenticated user can craft a specially formatted request path to bypass role-based restrictions and reach administrative or role gated endpoints they should not have access to. This affects all restricted paths protected by the RBAC authorization layer, including file upload, PHP server, htadmin, and authentication management interfaces.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Malcolmto a version that resolves this vulnerability.Fixed in v26.08.0
Event History
Frequently Asked Questions
What level of access does an attacker need?
The attacker needs an authenticated Malcolm account with low privileges. The attack can be performed over the network and does not require user interaction.
What could an attacker access if exploitation succeeds?
An attacker may bypass role-based restrictions on endpoints protected by the RBAC layer, including file upload, PHP server, htadmin, and authentication management interfaces. This can expose administrative or otherwise role-gated functionality.
Which deployments are exposed?
Deployments are exposed where Malcolm's nginx-based reverse proxy uses the affected Lua-based RBAC authorization layer to protect restricted paths. The supplied information does not identify unaffected configurations or versions.