CVE-2026-107334 — Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g.
Description
Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /auth, /admin_login, /arkime/api/esadmin, NetBox, upload endpoints) by pattern-matching the raw, percent-encoded request URI. Nginx itself, however, selects which location block actually serves the request using the percent-decoded, normalized URI. Because the RBAC check never percent-decodes its input, an authenticated low-privilege user can request an admin-only path using percent-encoding (e.g. /%68tadmin.php) and have nginx route it to the restricted location while the Lua RBAC gate evaluating the un-decoded raw string finds no matching restriction and grants access.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
Low
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
Low
Confidentiality
I
Low
Integrity
A
None
Availability
References
Related threats
same CWE or vendorCVE-2026-107706 — Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read per…
CVE-2026-107706 · 2h ago
CVE-2026-97147 — In OpenStack Mistral through 23.0.0, several of the v2 API write paths resolve the target object with a query that can return another project's res…
CVE-2026-97147 · 4h ago
CVE-2026-93861 — In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that has accepted a share of another project's private workflow cre…
CVE-2026-93861 · 4h ago
CVE-2026-107336 — Malcolm's front nginx reverse proxy defines a "Dashboards → Arkime shortcut" location using a case-insensitive regex matcher but a case-sensitive r…
CVE-2026-107336 · 4h ago
CVE-2026-107333 — Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authoriz…
CVE-2026-107333 · 4h ago
CVE-2026-50055 — A policy-enforcement flaw in Zimbra Collaboration Suite allows an authenticated user to bypass disabled mail forwarding by using a Sieve notify act…
CVE-2026-50055 · 5h ago