CVE-2026-107334: Incorrect Authorization in Malcolm
Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /auth, /adminlogin, /arkime/api/esadmin, NetBox, upload endpoints) by pattern-matching the raw, percent-encoded request URI. Nginx itself, however, selects which location block actually serves the request using the percent-decoded, normalized URI. Because the RBAC check never percent-decodes its input, an authenticated low-privilege user can request an admin-only path using percent-encoding (e.g. /%68tadmin.php) and have nginx route it to the restricted location while the Lua RBAC gate evaluating the un-decoded raw string finds no matching restriction and grants access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Malcolmto a version that resolves this vulnerability.Fixed in v26.08.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated low-privilege user can exploit it. The vulnerable check applies to role-restricted paths, including administrative, authentication, upload, NetBox, and Arkime Elasticsearch API endpoints.
What does an attacker need to send?
The attacker must request a restricted path with percent-encoded characters so that the raw URI does not match the Lua RBAC restriction pattern, while nginx decodes and normalizes it to the protected location. An example is requesting /%68tadmin.php instead of /htadmin.php.
Does this require user interaction or a complex attack path?
No user interaction is required, and the attack complexity is low. The attacker does need valid authentication as a low-privilege user.
How can defenders identify potentially affected access attempts?
Review requests to protected endpoints for percent-encoded path characters, particularly where the raw request URI differs from the decoded path nginx ultimately serves. Requests such as /%68tadmin.php targeting an administrative location are a relevant indicator.