CVE-2026-19670Patch

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /auth, /admin_login, /arkime/api/esadmin, NetBox, upload endpoints) by pattern-matching the raw, percent-encoded request URI. Nginx itself, however, selects which location block actually serves the request using the percent-decoded, normalized URI. Because the RBAC check never percent-decodes its input, an authenticated low-privilege user can request an admin-only path using percent-encoding (e.g. /%68tadmin.php) and have nginx route it to the restricted location while the Lua RBAC gate evaluating the un-decoded raw string finds no matching restriction and grants access.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-18: 1Patch / Workaround · 2026-08-18: 108-18
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity CISA Malcolm Vulnerabilities (CVE-2026-19670/19671 & Others): Detection and Rem… "CISA has published ICS Advisory ICSA-26-230-01 covering six vulnerabilities in Malcolm, CISA's…" 🔗 https://securityarsenal.com/blog/cisa-malcolm-vulnerabilities-cve-2026-1967019671-and-others-detection-and-remediation-guide-for-six-flaws-in-cisas-network-traffic-analysis-platform #CyberSecurity #ThreatIntel #critical #zeroday #cve

    Post summary

    CISA has issued advisory ICSA-26-230-01 covering six Malcolm vulnerabilities (CVE‑2026‑19670/19671) and provided detection and remediation guidance.

    0000038
    26 followersView on X

Explore more