The Arkime live capture service (arkime-live) in Malcolm runs with network_mode: host, exposing port 8005 on all network interfaces (viewHost=0.0.0.0). Arkime trusts the X-Forwarded-User header from any IP address (userAuthIps=::,0.0.0.0/0) and auto-creates users with full access. The passwordSecret is hardcoded to the public value "Malcolm". A network-adjacent attacker bypasses nginx entirely by connecting directly to port 8005 with a forged identity header.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update to version v26.08.0
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Arkime live capture service (arkime-live) in Malcolm runs with network_mode: host, exposing port 8005 on all network interfaces (viewHost=0.0.0.0). Arkime trusts the X-Forwarded-User header from any IP address (userAuthIps=::,0.0.0.0/0) and auto-creates users with full access. The passwordSecret is hardcoded to the public value "Malcolm". A network-adjacent attacker bypasses nginx entirely by connecting directly to port 8005 with a forged identity header. | |
| Title | Authentication Bypass Using an Alternate Path or Channel in Malcolm | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-10-08T19:09:10.459Z
Reserved: 2026-10-07T20:08:34.511Z
Link: CVE-2026-107361
No data.
Status : Received
Published: 2026-10-08T18:17:21.170
Modified: 2026-10-08T18:17:21.170
Link: CVE-2026-107361
No data.
OpenCVE Enrichment
Updated: 2026-10-08T19:15:20Z
Weaknesses