Exposure of the Arkime Live Capture Service in Malcolm by CISA
CVE-2026-107361

4.2MEDIUM

Key Information:

Vendor

Cisa

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107361?

The Arkime live capture service in Malcolm poses significant security risks due to its configuration. With network_mode set to host, the service exposes port 8005 to all network interfaces, allowing potential attackers to directly access the service. Additionally, the application trusts the X-Forwarded-User header from any IP address without proper validation, enabling the creation of users with full access rights automatically. Compounding these vulnerabilities, the default password is hardcoded to 'Malcolm', which is easily guessable. These flaws could allow a network-adjacent attacker to bypass existing protections and gain unauthorized access.

Affected Version(s)

Malcolm 0 <= 26.07.1

Malcolm 26.08.0

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Seth Grover
.