What is CVE-2026-19670?
CVE-2026-19670 allows bypassing Malcolm's nginx Lua RBAC layer by exploiting pattern-matching on raw, percent-encoded request URIs to access role-restricted paths like /htadmin or /auth. This could lead to unauthorized access to sensitive endpoints. Affected systems should update the nginx configuration and upgrade Malcolm to the latest version.
Azərbaycanca: CVE-2026-19670 Malcolm-un nginx Lua RBAC qatında autentifikasiya olunmuş istifadəçilərin məhdud yollara çıxışını idarə edərkən raw, percent-encoded request URI-nin pattern-matching zəifliyindən istifadə edərək yan keçməyə imkan verir. Bu, /htadmin, /auth, /admin_login kimi həssas yollara icazəsiz girişə səbəb ola bilər. Təsirə məruz qalan sistemlərdə nginx konfiqurasiyasını yeniləmək və Malcolm-u ən son versiyaya yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
How does CVE-2026-19670 allow bypassing Malcolm's nginx Lua RBAC layer?
CVE-2026-19670 allows bypassing the RBAC layer by exploiting a pattern-matching weakness on raw, percent-encoded request URIs.
Which sensitive endpoints can an attacker gain unauthorized access to by exploiting CVE-2026-19670?
An attacker can gain unauthorized access to sensitive endpoints such as /htadmin, /auth, or /admin_login by exploiting this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.