Role-Based Access Control Vulnerability in Malcolm's Nginx Lua for Limited Privilege Users
CVE-2026-107334
5.4MEDIUM
What is CVE-2026-107334?
Malcolm's Nginx Lua role-based access control (RBAC) implementation is designed to restrict access to sensitive paths based on user roles. However, the vulnerability arises from the method by which it evaluates permissions. The RBAC system matches the raw, percent-encoded request URIs against its defined rules, while Nginx utilizes the percent-decoded, normalized URI to determine the actual routing. This discrepancy allows an authenticated low-privilege user to gain access to restricted admin paths through the use of encoded requests, bypassing the intended access controls and potentially exposing sensitive areas of the application.
Affected Version(s)
Malcolm 0 <= 26.07.1
Malcolm 26.08.0
