CVE-2026-107361: CWE-288 Authentication bypass using an alternate path or channel in CISA Malcolm
Description
The Arkime live capture service (arkime-live) in Malcolm runs with network_mode: host, exposing port 8005 on all network interfaces (viewHost=0.0.0.0). Arkime trusts the X-Forwarded-User header from any IP address (userAuthIps=::,0.0.0.0/0) and auto-creates users with full access. The passwordSecret is hardcoded to the public value "Malcolm". A network-adjacent attacker bypasses nginx entirely by connecting directly to port 8005 with a forged identity header.
CVSS v3.1
Score 4.2medium
Affected software
CISA
Malcolm
pkg:github/cisagov/MalcolmRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises because arkime-live in Malcolm is configured to trust the X-Forwarded-User header from any IP address, combined with a hardcoded public passwordSecret. The service exposes port 8005 on all network interfaces in host network mode. This allows a network-adjacent attacker to bypass the nginx proxy entirely by connecting directly to port 8005 and forging the identity header, resulting in authentication bypass and automatic creation of users with full access privileges.
Potential Impact
An attacker with network adjacency can bypass authentication controls by directly connecting to the exposed port 8005 and forging the X-Forwarded-User header. This leads to unauthorized access with full privileges, potentially compromising confidentiality and integrity of the system. The CVSS 3.1 score is 4.2 (medium severity) reflecting low impact on confidentiality and integrity, no impact on availability, and requiring high attack complexity with no privileges or user interaction.
Mitigation Recommendations
No official patch or fix is currently available as per the provided data. Users should restrict network access to port 8005 to trusted hosts only and avoid exposing the service on all interfaces. Additionally, avoid using the default hardcoded passwordSecret and configure proper authentication mechanisms. Monitor vendor advisories for updates or official fixes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- icscert
- Date Reserved
- 2026-10-07T20:08:34.511Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac7d49a2cdf04f6562c68ae
Added to database: 10/08/2026, 17:36:26 UTC
Last enriched: 10/08/2026, 17:48:47 UTC
Last updated: 10/08/2026, 21:45:56 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.