CVE-2026-107336 — Malcolm's front nginx reverse proxy defines a "Dashboards → Arkime shortcut" location using a case-insensitive regex matcher but a case-sensitive r…
Description
Malcolm's front nginx reverse proxy defines a "Dashboards → Arkime shortcut" location using a case-insensitive regex matcher but a case-sensitive rewrite. A request whose path segment is not exact-lowercase (for example /IDDASH2ARK/...) enters the location (the matcher fires) but evades the rewrite (no redirect is issued), so nginx falls through to the location's proxy_pass to the Arkime backend. That location is the one proxied location in the shipped config that does not include the per-location authentication file, so the request reaches Arkime unauthenticated. The same location also forwards a client-supplied X-Forwarded-User header un-overwritten, and Arkime is configured to trust X-Forwarded-User as the authenticated username — so an unauthenticated network caller can reach the Arkime backend while supplying a forged, auto-provisioned identity.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
Low
Confidentiality
I
Low
Integrity
A
None
Availability
References
Related threats
same CWE or vendorCVE-2026-107706 — Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read per…
CVE-2026-107706 · 2h ago
CVE-2026-97147 — In OpenStack Mistral through 23.0.0, several of the v2 API write paths resolve the target object with a query that can return another project's res…
CVE-2026-97147 · 4h ago
CVE-2026-93861 — In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that has accepted a share of another project's private workflow cre…
CVE-2026-93861 · 4h ago
CVE-2026-107334 — Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g.
CVE-2026-107334 · 4h ago
CVE-2026-107333 — Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authoriz…
CVE-2026-107333 · 4h ago
CVE-2026-50055 — A policy-enforcement flaw in Zimbra Collaboration Suite allows an authenticated user to bypass disabled mail forwarding by using a Sieve notify act…
CVE-2026-50055 · 5h ago