What is CVE-2026-63177?
CVE-2026-63177: A vulnerability in the Malcolm network traffic analysis tool suite stems from its role-based access control mechanism evaluating the raw, unnormalized `ngx.var.request_uri` instead of the normalized path used by Nginx for routing. Affecting versions before 26.07.0, this allows an authenticated low-privilege user to potentially bypass access restrictions by crafting specific HTTP requests. Upgrading to version 26.07.0 or later is strongly recommended.
Azərbaycanca: CVE-2026-63177: Malcolm şəbəkə trafik analizi alət dəstində aşkarlanan zəiflik "role-based access control" (RBAC) mexanizminin `ngx.var.request_uri` dəyərini normallaşdırmadan istifadə etməsindən qaynaqlanır. 26.07.0 versiyasından əvvəlki Malcolm qurğuları təsirlənir - autentifikasiya olunmuş aşağı səlahiyyətli istifadəçi, xüsusi hazırlanmış HTTP sorğuları ilə bu məntiq qüsurundan istifadə edərək giriş məhdudiyyətlərini keçə bilər. Təsirə məruz qalan sistemləri Malcolm 26.07.0 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Does exploiting CVE-2026-63177 require the attacker to be authenticated?
Yes, exploiting this vulnerability requires the attacker to be authenticated as a low-privilege user on the system.
To which version should Malcolm be upgraded to mitigate CVE-2026-63177?
To mitigate the vulnerability, Malcolm should be upgraded to version 26.07.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.