Case-Sensitive Rewrite Issue in Malcolm’s Arkime Backend
CVE-2026-107336

6.5MEDIUM

Key Information:

Vendor

Cisa

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107336?

A vulnerability exists in Malcolm's nginx reverse proxy configuration that allows unauthenticated access to the Arkime backend. The 'Dashboards → Arkime shortcut' location is defined using a case-insensitive regex matcher, but the rewrite rule is case-sensitive. This discrepancy allows requests with path segments that are not strictly lowercase to bypass the intended authentication mechanism. Consequently, an attacker can send malformed requests to the backend without proper authentication, potentially compromising the integrity of the system. Furthermore, the configuration forwards a client-supplied X-Forwarded-User header, which is trusted by Arkime, enabling an unauthorized user to impersonate a legitimate identity.

Affected Version(s)

Malcolm 0 <= 26.07.1

Malcolm 26.08.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Seth Grover
.