CVE-2026-63177: CWE-863: Incorrect Authorization in cisagov Malcolm
CVE-2026-63177 is an authorization vulnerability in cisagov Malcolm, a network traffic analysis tool. Before version 26.07.0, the role-based access control in the Nginx OpenResty Lua layer evaluates the raw request URI without normalization, while Nginx routes requests using a normalized path. This discrepancy allows an authenticated low-privilege user to bypass access controls by using path traversal segments, gaining unauthorized access to restricted backend resources. The issue is fixed in version 26.07.0.
AI Analysis
Technical Summary
Malcolm versions prior to 26.07.0 suffer from an incorrect authorization vulnerability (CWE-863) due to inconsistent URI normalization between Nginx routing and the Lua layer enforcing role-based access control. The Lua layer checks the raw, unnormalized request URI, while Nginx routes requests based on the normalized path. An attacker with low privileges can prepend traversal sequences (e.g., /x/../upload/...) to bypass authorization checks, gaining access to restricted backend endpoints. This vulnerability has a CVSS 3.1 score of 7.1 (high severity) with network attack vector, low attack complexity, and requires low privileges but no user interaction. The vulnerability is fixed in Malcolm version 26.07.0.
Potential Impact
An authenticated user with low privileges can exploit this vulnerability to bypass role-based access controls and gain unauthorized access to restricted backend resources. This can lead to unauthorized data disclosure (high confidentiality impact) and limited integrity impact. There is no impact on availability. No known exploits are reported in the wild.
Mitigation Recommendations
Upgrade Malcolm to version 26.07.0 or later, where this authorization bypass issue is fixed. Patch status is not explicitly stated but the vendor has released version 26.07.0 to address the vulnerability. No other mitigations are indicated.
CVE-2026-63177: CWE-863: Incorrect Authorization in cisagov Malcolm
Description
CVE-2026-63177 is an authorization vulnerability in cisagov Malcolm, a network traffic analysis tool. Before version 26.07.0, the role-based access control in the Nginx OpenResty Lua layer evaluates the raw request URI without normalization, while Nginx routes requests using a normalized path. This discrepancy allows an authenticated low-privilege user to bypass access controls by using path traversal segments, gaining unauthorized access to restricted backend resources. The issue is fixed in version 26.07.0.
CVSS v3.1
Score 7.1high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Malcolm versions prior to 26.07.0 suffer from an incorrect authorization vulnerability (CWE-863) due to inconsistent URI normalization between Nginx routing and the Lua layer enforcing role-based access control. The Lua layer checks the raw, unnormalized request URI, while Nginx routes requests based on the normalized path. An attacker with low privileges can prepend traversal sequences (e.g., /x/../upload/...) to bypass authorization checks, gaining access to restricted backend endpoints. This vulnerability has a CVSS 3.1 score of 7.1 (high severity) with network attack vector, low attack complexity, and requires low privileges but no user interaction. The vulnerability is fixed in Malcolm version 26.07.0.
Potential Impact
An authenticated user with low privileges can exploit this vulnerability to bypass role-based access controls and gain unauthorized access to restricted backend resources. This can lead to unauthorized data disclosure (high confidentiality impact) and limited integrity impact. There is no impact on availability. No known exploits are reported in the wild.
Mitigation Recommendations
Upgrade Malcolm to version 26.07.0 or later, where this authorization bypass issue is fixed. Patch status is not explicitly stated but the vendor has released version 26.07.0 to address the vulnerability. No other mitigations are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-15T22:13:00.720Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7b8c91bf8831d539668d2f
Added to database: 08/11/2026, 20:56:49 UTC
Last enriched: 08/11/2026, 21:11:07 UTC
Last updated: 08/11/2026, 21:19:39 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.