PT-2026-77277 · Malcolm+1 · Malcolm+1

·

CVE-2026-19670

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Malcolm (affected versions not specified)
Description The nginx Lua role-based access control (RBAC) layer fails to percent-decode the request URI before performing pattern-matching to restrict access to sensitive paths. While the RBAC gate evaluates the raw, percent-encoded string, nginx uses the percent-decoded, normalized URI to route the request to the appropriate location block. This discrepancy allows an authenticated user with low privileges to bypass access restrictions by using percent-encoding in the request URI, such as requesting /%68tadmin.php instead of /htadmin.php, to reach restricted endpoints like /htadmin, /auth, /admin login, /arkime/api/esadmin, NetBox, and upload endpoints.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19670
GHSA-F2V6-8CJ4-MHR6

Affected Products

Malcolm
Nginx