CVE-2026-107361
Received Received - Intake

Arkime Live Capture Service Authentication Bypass

Vulnerability report for CVE-2026-107361, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: ICS-CERT

Description

The Arkime live capture service (arkime-live) in Malcolm runs with network_mode: host, exposing port 8005 on all network interfaces (viewHost=0.0.0.0). Arkime trusts the X-Forwarded-User header from any IP address (userAuthIps=::,0.0.0.0/0) and auto-creates users with full access. The passwordSecret is hardcoded to the public value "Malcolm". A network-adjacent attacker bypasses nginx entirely by connecting directly to port 8005 with a forged identity header.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
CISA Malcolm 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-288 The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Arkime live capture service (arkime-live) in Malcolm runs with network_mode: host, exposing port 8005 on all network interfaces. Arkime trusts the X-Forwarded-User header from any IP address and auto-creates users with full access. The passwordSecret is hardcoded to 'Malcolm'. A network-adjacent attacker can bypass nginx by connecting directly to port 8005 with a forged identity header.

Detection Guidance

Check if port 8005 is open and accessible on any network interface using netstat or ss. Example: netstat -tulnp | grep 8005 or ss -tulnp | grep 8005. Verify if Arkime is running with network_mode: host in its configuration.

Impact Analysis

An attacker on the same network can gain unauthorized access to the Arkime service with full privileges. They can forge the X-Forwarded-User header to impersonate any user, including administrators, and perform actions without authentication. The hardcoded password 'Malcolm' further weakens security.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and access control. It allows unauthorized access to sensitive data, which could lead to data breaches. GDPR and HIPAA require strict access controls and protection of personal health information, which this flaw undermines.

Mitigation Strategies

Disable network_mode: host for Arkime and bind it to localhost only. Restrict access to port 8005 using firewall rules. Change the hardcoded passwordSecret from 'Malcolm' to a strong, unique value. Disable user auto-creation and validate X-Forwarded-User headers from trusted IPs only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107361. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart