PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107361 CISA CVE debrief

CVE-2026-107361 is an authentication bypass vulnerability in the Arkime live capture service (arkime-live) of Malcolm, a tool developed by CISA. The vulnerability allows a network-adjacent attacker to bypass authentication by connecting directly to port 8005 with a forged identity header, potentially gaining full access to the system. This is possible because Arkime runs with network_mode: host, exposing port 8005 on all network interfaces, and trusts the X-Forwarded-User header from any IP address, auto-creating users with full access. The passwordSecret is hardcoded to the public value 'Malcolm'. Defenders should verify exposure, update to a patched version, and consider network

Vendor
CISA
Product
Malcolm
CVSS
MEDIUM 4.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for Malcolm deployments, network administrators, and security teams should be aware of this vulnerability and take steps to verify exposure and mitigate potential risks.

Why it matters

CVE-2026-107361 is a medium-severity authentication bypass vulnerability in Malcolm's Arkime live capture service. Defenders should verify exposure, update to a patched version, and consider additional security measures to prevent potential exploitation and limit damage.

  • Network-adjacent attackers may bypass authentication and gain unauthorized access to the system.
  • Vulnerable versions of Malcolm (prior to 26.08.0) are susceptible to exploitation.
  • Defenders need to verify exposure and update to a patched version to prevent potential exploitation.
  • Additional security measures, such as network segmentation or access controls, may be necessary to limit potential damage.

Technical summary

The Arkime live capture service (arkime-live) in Malcolm runs with network_mode: host, exposing port 8005 on all network interfaces. Arkime trusts the X-Forwarded-User header from any IP address and auto-creates users with full access. The passwordSecret is hardcoded to the public value 'Malcolm'. A network-adjacent attacker bypasses nginx entirely by connecting directly to port 8005 with a forged identity header.

Defensive priority

Defenders should prioritize verifying exposure of Malcolm's Arkime live capture service, especially in network environments where the service is accessible. They should also assess the system's configuration and update to version 26.08.0 or later if currently using a vulnerable version.

Recommended defensive actions

  • Verify exposure of Malcolm's Arkime live capture service in your network environment.
  • Assess the system's configuration and check if it is using a vulnerable version (prior to 26.08.0).
  • Update to version 26.08.0 or later if currently using a vulnerable version.
  • Monitor network traffic to port 8005 for suspicious activity.
  • Consider implementing additional security measures, such as network segmentation or access controls, to limit potential damage.

Evidence notes

The CVE record and source item provide details about the vulnerability, including its description, CVSS score, and affected versions. However, there is limited information about potential exploits or impacts, and no specific details about victim organizations or data breaches.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107361 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107361

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107361 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107361

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Authentication Bypass Using an Alternate Path or Channel in Malcolm

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107361.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/cisagov/Malcolm/security/advisories/GHSA-86h3-7rf8-8j34

    Supplemental source - government-resource

  • Source reference

    Unverified legacy reference

    URL: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-280-01.json

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.