PatchSiren cyber security CVE debrief
CVE-2026-107361 CISA CVE debrief
CVE-2026-107361 is an authentication bypass vulnerability in the Arkime live capture service (arkime-live) of Malcolm, a tool developed by CISA. The vulnerability allows a network-adjacent attacker to bypass authentication by connecting directly to port 8005 with a forged identity header, potentially gaining full access to the system. This is possible because Arkime runs with network_mode: host, exposing port 8005 on all network interfaces, and trusts the X-Forwarded-User header from any IP address, auto-creating users with full access. The passwordSecret is hardcoded to the public value 'Malcolm'. Defenders should verify exposure, update to a patched version, and consider network
- Vendor
- CISA
- Product
- Malcolm
- CVSS
- MEDIUM 4.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for Malcolm deployments, network administrators, and security teams should be aware of this vulnerability and take steps to verify exposure and mitigate potential risks.
Why it matters
CVE-2026-107361 is a medium-severity authentication bypass vulnerability in Malcolm's Arkime live capture service. Defenders should verify exposure, update to a patched version, and consider additional security measures to prevent potential exploitation and limit damage.
- Network-adjacent attackers may bypass authentication and gain unauthorized access to the system.
- Vulnerable versions of Malcolm (prior to 26.08.0) are susceptible to exploitation.
- Defenders need to verify exposure and update to a patched version to prevent potential exploitation.
- Additional security measures, such as network segmentation or access controls, may be necessary to limit potential damage.
Technical summary
The Arkime live capture service (arkime-live) in Malcolm runs with network_mode: host, exposing port 8005 on all network interfaces. Arkime trusts the X-Forwarded-User header from any IP address and auto-creates users with full access. The passwordSecret is hardcoded to the public value 'Malcolm'. A network-adjacent attacker bypasses nginx entirely by connecting directly to port 8005 with a forged identity header.
Defensive priority
Defenders should prioritize verifying exposure of Malcolm's Arkime live capture service, especially in network environments where the service is accessible. They should also assess the system's configuration and update to version 26.08.0 or later if currently using a vulnerable version.
Recommended defensive actions
- Verify exposure of Malcolm's Arkime live capture service in your network environment.
- Assess the system's configuration and check if it is using a vulnerable version (prior to 26.08.0).
- Update to version 26.08.0 or later if currently using a vulnerable version.
- Monitor network traffic to port 8005 for suspicious activity.
- Consider implementing additional security measures, such as network segmentation or access controls, to limit potential damage.
Evidence notes
The CVE record and source item provide details about the vulnerability, including its description, CVSS score, and affected versions. However, there is limited information about potential exploits or impacts, and no specific details about victim organizations or data breaches.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107361 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107361
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107361 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107361
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Authentication Bypass Using an Alternate Path or Channel in Malcolm
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107361.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/cisagov/Malcolm/security/advisories/GHSA-86h3-7rf8-8j34
Supplemental source - government-resource
-
Source reference
Unverified legacy reference
URL: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-280-01.json
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.