PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107336 CISA CVE debrief

A vulnerability in Malcolm allows for authentication bypass by spoofing. The front nginx reverse proxy has a case-insensitive regex matcher but a case-sensitive rewrite, which can be exploited to reach the Arkime backend unauthenticated. The vulnerability has a CVSS score of 6.5 and is considered medium severity. Defenders should assess their exposure and verify the authenticity of requests to the Arkime backend. The vulnerability allows an attacker to evade authentication and reach the Arkime backend without proper validation of the X-Forwarded-User header. This can lead to unauthorized access and potential security breaches.

Vendor
CISA
Product
Malcolm
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for the security of Malcolm installations should assess their exposure and verify the authenticity of requests to the Arkime backend. They should prioritize verifying the authenticity of requests and ensuring that the X-Forwarded-User header is properly validated. This includes reviewing and updating the nginx configuration to prevent similar vulnerabilities and ensuring that compensating controls are in place for exposed systems.

Why it matters

The vulnerability allows for authentication bypass by spoofing, which can lead to unauthorized access to the Arkime backend. Defenders should prioritize verifying the authenticity of requests and ensuring that the X-Forwarded-User header is properly validated.

  • An attacker can reach the Arkime backend unauthenticated
  • The X-Forwarded-User header can be forged to auto-provision an identity
  • Defenders need to verify the authenticity of requests to the Arkime backend
  • Defenders need to ensure that the X-Forwarded-User header is properly validated

Technical summary

The vulnerability is caused by a case-insensitive regex matcher and a case-sensitive rewrite in the front nginx reverse proxy. This allows an attacker to evade authentication and reach the Arkime backend unauthenticated. The vulnerability has a CVSS score of 6.5 and is considered medium severity. The Arkime backend does not include per-location authentication, and the X-Forwarded-User header is trusted as the authenticated username. An attacker can exploit this vulnerability by supplying a forged X-Forwarded-User header to auto-provision an identity.

Defensive priority

Defenders should prioritize verifying the authenticity of requests to the Arkime backend and ensuring that the X-Forwarded-User header is properly validated.

Recommended defensive actions

  • Verify the authenticity of requests to the Arkime backend
  • Ensure that the X-Forwarded-User header is properly validated
  • Review and update the nginx configuration to prevent similar vulnerabilities
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The vulnerability is caused by a case-insensitive regex matcher and a case-sensitive rewrite in the front nginx reverse proxy. This allows an attacker to evade authentication and reach the Arkime backend unauthenticated.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107336 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107336

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107336 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107336

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Authentication Bypass by Spoofing in Malcolm

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107336.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/cisagov/Malcolm/security/advisories/GHSA-7j32-cf27-cp6h

    Supplemental source - government-resource

  • Source reference

    Unverified legacy reference

    URL: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-280-01.json

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.