Case-Sensitive Rewrite Issue in Malcolm’s Arkime Backend
CVE-2026-107336
What is CVE-2026-107336?
A vulnerability exists in Malcolm's nginx reverse proxy configuration that allows unauthenticated access to the Arkime backend. The 'Dashboards → Arkime shortcut' location is defined using a case-insensitive regex matcher, but the rewrite rule is case-sensitive. This discrepancy allows requests with path segments that are not strictly lowercase to bypass the intended authentication mechanism. Consequently, an attacker can send malformed requests to the backend without proper authentication, potentially compromising the integrity of the system. Furthermore, the configuration forwards a client-supplied X-Forwarded-User header, which is trusted by Arkime, enabling an unauthorized user to impersonate a legitimate identity.
Affected Version(s)
Malcolm 0 <= 26.07.1
Malcolm 26.08.0
