Exposure of the Arkime Live Capture Service in Malcolm by CISA
CVE-2026-107361
4.2MEDIUM
What is CVE-2026-107361?
The Arkime live capture service in Malcolm poses significant security risks due to its configuration. With network_mode set to host, the service exposes port 8005 to all network interfaces, allowing potential attackers to directly access the service. Additionally, the application trusts the X-Forwarded-User header from any IP address without proper validation, enabling the creation of users with full access rights automatically. Compounding these vulnerabilities, the default password is hardcoded to 'Malcolm', which is easily guessable. These flaws could allow a network-adjacent attacker to bypass existing protections and gain unauthorized access.
Affected Version(s)
Malcolm 0 <= 26.07.1
Malcolm 26.08.0
