PT-2026-77277 · Malcolm+1 · Malcolm+1
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Malcolm (affected versions not specified)
Description
The nginx Lua role-based access control (RBAC) layer fails to percent-decode the request URI before performing pattern-matching to restrict access to sensitive paths. While the RBAC gate evaluates the raw, percent-encoded string, nginx uses the percent-decoded, normalized URI to route the request to the appropriate location block. This discrepancy allows an authenticated user with low privileges to bypass access restrictions by using percent-encoding in the request URI, such as requesting
/%68tadmin.php instead of /htadmin.php, to reach restricted endpoints like /htadmin, /auth, /admin login, /arkime/api/esadmin, NetBox, and upload endpoints.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Malcolm
Nginx