PatchSiren cyber security CVE debrief
CVE-2026-107336 CISA CVE debrief
A vulnerability in Malcolm allows for authentication bypass by spoofing. The front nginx reverse proxy has a case-insensitive regex matcher but a case-sensitive rewrite, which can be exploited to reach the Arkime backend unauthenticated. The vulnerability has a CVSS score of 6.5 and is considered medium severity. Defenders should assess their exposure and verify the authenticity of requests to the Arkime backend. The vulnerability allows an attacker to evade authentication and reach the Arkime backend without proper validation of the X-Forwarded-User header. This can lead to unauthorized access and potential security breaches.
- Vendor
- CISA
- Product
- Malcolm
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for the security of Malcolm installations should assess their exposure and verify the authenticity of requests to the Arkime backend. They should prioritize verifying the authenticity of requests and ensuring that the X-Forwarded-User header is properly validated. This includes reviewing and updating the nginx configuration to prevent similar vulnerabilities and ensuring that compensating controls are in place for exposed systems.
Why it matters
The vulnerability allows for authentication bypass by spoofing, which can lead to unauthorized access to the Arkime backend. Defenders should prioritize verifying the authenticity of requests and ensuring that the X-Forwarded-User header is properly validated.
- An attacker can reach the Arkime backend unauthenticated
- The X-Forwarded-User header can be forged to auto-provision an identity
- Defenders need to verify the authenticity of requests to the Arkime backend
- Defenders need to ensure that the X-Forwarded-User header is properly validated
Technical summary
The vulnerability is caused by a case-insensitive regex matcher and a case-sensitive rewrite in the front nginx reverse proxy. This allows an attacker to evade authentication and reach the Arkime backend unauthenticated. The vulnerability has a CVSS score of 6.5 and is considered medium severity. The Arkime backend does not include per-location authentication, and the X-Forwarded-User header is trusted as the authenticated username. An attacker can exploit this vulnerability by supplying a forged X-Forwarded-User header to auto-provision an identity.
Defensive priority
Defenders should prioritize verifying the authenticity of requests to the Arkime backend and ensuring that the X-Forwarded-User header is properly validated.
Recommended defensive actions
- Verify the authenticity of requests to the Arkime backend
- Ensure that the X-Forwarded-User header is properly validated
- Review and update the nginx configuration to prevent similar vulnerabilities
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability is caused by a case-insensitive regex matcher and a case-sensitive rewrite in the front nginx reverse proxy. This allows an attacker to evade authentication and reach the Arkime backend unauthenticated.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107336 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107336
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107336 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107336
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Authentication Bypass by Spoofing in Malcolm
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107336.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/cisagov/Malcolm/security/advisories/GHSA-7j32-cf27-cp6h
Supplemental source - government-resource
-
Source reference
Unverified legacy reference
URL: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-280-01.json
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.