CVE-2026-107333

Source
https://cve.org/CVERecord?id=CVE-2026-107333
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107333.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107333
Aliases
  • GHSA-v66f-cwcm-hf73
Published
2026-10-08T17:23:14Z
Modified
2026-10-10T02:47:27Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Incorrect Authorization in Malcolm
Details

Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authorization layer and nginx's own request routing logic. An authenticated user can craft a specially formatted request path to bypass role-based restrictions and reach administrative or role gated endpoints they should not have access to. This affects all restricted paths protected by the RBAC authorization layer, including file upload, PHP server, htadmin, and authentication management interfaces.

Database specific
{
    "cna_assigner": "icscert",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107333.json"
}
References

Affected packages

Git / github.com/cisagov/malcolm

Affected ranges

Type
GIT
Repo
https://github.com/cisagov/malcolm
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "26.07.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v1.*
v1.2.0
v1.2.1
v1.2.2
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.5.1
v1.5.2
v1.6.0
v1.7.0
v1.7.1
v1.7.1a
v1.7.2
v1.8.0
v1.8.1
v2.*
v2.0.0
v2.0.0-pre1
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.4.0
v2.4.0.1
v2.4.1
v2.4.2
v2.5.0
v2.6.0
v2.6.1
v26.*
v26.05.2
v26.06.0
v26.06.1
v26.07.0
v26.07.1
v3.*
v3.0.0
v3.0.1
v5.*
v5.2.1
v5.2.2
v5.2.3
v5.2.4
v6.*
v6.4.0
v6.4.1
v6.4.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107333.json"