Junglewise Threat Intelligence

CVE-2026-19670: CISA Malcolm nginx Lua RBAC bypass via percent-encoding

CVE-2026-19670 · Severity: medium · CVSS 5.4 · Published 2026-08-18

Executive brief

Malcolm is a network traffic analysis platform used to monitor and investigate network communications. Its authentication layer validates user access to restricted administrative paths, but fails to properly decode URL-encoded characters before checking permissions. An authenticated low-privilege user can request admin-only pages using URL encoding tricks (e.g., /%68tadmin instead of /htadmin) to bypass access controls and reach sensitive functionality they should not have access to.

Technical details

The vulnerability is an authorization bypass in Malcolm's nginx Lua RBAC layer caused by inconsistent URL decoding between the access control check and nginx's request routing logic. The Lua gate evaluates restrictions against the raw, percent-encoded request URI, while nginx itself routes requests using the decoded and normalized URI. An authenticated attacker can percent-encode path components (e.g., %68 for 'h') so the Lua check sees no matching restriction pattern and grants access, but nginx then routes the request to the restricted location block. This affects admin paths including /htadmin, /auth, /admin_login, /arkime/api/esadmin, NetBox, and upload endpoints. The fix requires the RBAC layer to decode URIs before pattern matching.

Affected products

  • CISA Malcolm <=26.07.1

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: advisory: CISA ICSA-26-230-01

References

Related threats