Access Control Flaw in Malcolm Network Traffic Analysis Tool by CISA
CVE-2026-63177

7.1HIGH

Key Information:

Vendor

Cisagov

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-63177?

The Malcolm network traffic analysis tool suite contains a flaw where its role-based access control, implemented in the Nginx OpenResty Lua layer, evaluates the raw request URI instead of the normalized path utilized by Nginx for routing. This implementation oversight allows an authenticated low-privilege user to manipulate the request URI. By prepending a traversal segment, they can route a request to a restricted backend resource that should be inaccessible. The Lua role validation fails to enforce the proper access rules, potentially granting unauthorized access to sensitive areas of the application. This issue was resolved in version 26.07.0.

Affected Version(s)

Malcolm < 26.07.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.