PatchSiren cyber security CVE debrief
CVE-2026-107334 CISA CVE debrief
CVE-2026-107334 is an Incorrect Authorization vulnerability in Malcolm, a tool from CISA. The vulnerability arises from a mismatch between how nginx and its Lua role-based access control (RBAC) layer handle URL encoding. Specifically, the RBAC layer checks access permissions based on the raw, percent-encoded request URI, while nginx uses the percent-decoded, normalized URI to determine which location block serves the request. This discrepancy allows an authenticated low-privilege user to access admin-only paths by percent-encoding the URL, potentially bypassing intended access restrictions.
- Vendor
- CISA
- Product
- Malcolm
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for the security of Malcolm deployments should be aware of this vulnerability and take steps to verify the presence of the vulnerability in their systems, assess the potential impact, and apply patches or updates as needed.
Why it matters
CVE-2026-107334 is an Incorrect Authorization vulnerability in Malcolm that allows low-privilege users to access admin-only paths via URL encoding. Defenders should verify the presence of this vulnerability, assess the potential impact, and prioritize patching or updating Malcolm to prevent unauthorized access.
- An authenticated low-privilege user may be able to access admin-only paths and perform actions that should be restricted.
- Defenders need to verify the presence of this vulnerability in their Malcolm deployments and assess the potential impact.
- The vulnerability requires verification of access controls and RBAC configurations to prevent unauthorized access.
- Patching or updating Malcolm to a version that addresses this vulnerability should be a priority.
Technical summary
The vulnerability is caused by a mismatch between how nginx and its Lua RBAC layer handle URL encoding. The RBAC layer checks access permissions based on the raw, percent-encoded request URI, while nginx uses the percent-decoded, normalized URI to determine which location block serves the request. This allows an authenticated low-privilege user to access admin-only paths by percent-encoding the URL.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their Malcolm deployments and assess the potential impact of unauthorized access to restricted paths.
Recommended defensive actions
- Verify the version of Malcolm in use and compare it to the affected versions listed in the CVE record.
- Review access controls and RBAC configurations to ensure that they are properly implemented and restrictive enough to prevent unauthorized access.
- Consider applying patches or updates provided by the vendor, if available.
- Monitor system logs for any suspicious activity related to URL encoding and access to restricted paths.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE record and source item provide details about the vulnerability, including its description, affected versions, and references to additional information. However, the corpus does not provide explicit information about exploitation or specific attacks.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107334 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107334
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107334 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107334
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Incorrect Authorization in Malcolm
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107334.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/cisagov/Malcolm/security/advisories/GHSA-jr6p-63pg-hr6g
Supplemental source - government-resource
-
Source reference
Unverified legacy reference
URL: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-280-01.json
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.