CVE-2026-107333
Received Received - Intake

Malcolm Reverse Proxy URL Path Normalization Bypass via RBAC Bypass

Vulnerability report for CVE-2026-107333, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: ICS-CERT

Description

Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authorization layer and nginx's own request routing logic. An authenticated user can craft a specially formatted request path to bypass role-based restrictions and reach administrative or role gated endpoints they should not have access to. This affects all restricted paths protected by the RBAC authorization layer, including file upload, PHP server, htadmin, and authentication management interfaces.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
CISA Malcolm 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in Malcolm's nginx reverse proxy. It occurs due to a mismatch in URL path normalization between the Lua-based RBAC authorization layer and nginx's request routing logic. An authenticated user can craft a request path with a specially formatted segment like /./ to bypass role-based access restrictions and access administrative endpoints they should not have permission to reach.

Detection Guidance

Check nginx access logs for unusual paths containing '/./' segments or requests to restricted endpoints like '/htadmin/', '/upload/', or '/pcap/export'. Use tools like curl to test paths with '/./' prefix to see if unauthorized access is granted.

Impact Analysis

An attacker with minimal privileges could gain unauthorized access to sensitive components such as file upload interfaces, account administration UI, or PCAP export endpoints. This could allow file injection or manipulation of evidence in network-monitoring environments if downstream services do not re-check roles.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data or administrative functions, potentially violating data protection requirements under GDPR or HIPAA. Unauthorized access to file uploads or evidence manipulation may result in non-compliance with access control and integrity requirements.

Mitigation Strategies

Update the normalize_uri_for_rbac() function in nginx_auth_helpers.lua to resolve both '.' and '..' segments. Alternatively, match the normalized URI (ngx.var.uri) or implement a fail-closed policy in nginx configuration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107333. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart