---
id: CVE-2026-107361
title: >-
  The Arkime live capture service (arkime-live) in Malcolm runs with
  network_mode: host, exposing port 8005 on all network interfaces
  (viewHost=0.0.0.0)
summary: >-
  The Arkime live capture service (arkime-live) in Malcolm runs with
  network_mode: host, exposing port 8005 on all network interfaces
  (viewHost=0.0.0.0). Arkime trusts the X-Forwarded-User header from any IP
  address (userAuthIps=::,0.0.0.0…
severity: medium
cvss: 4.2
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-288
vendor: CISA
product: Malcolm
affected:
  - Malcolm <= 26.07.1
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:03:43.847'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107361'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-280-01.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://github.com/cisagov/Malcolm/security/advisories/GHSA-86h3-7rf8-8j34'
    label: ics-cert@hq.dhs.gov
  - url: 'https://github.com/cisagov/Malcolm/security/advisories/GHSA-86h3-7rf8-8j34'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-08T17:56:11.738Z'
---

## Overview

The Arkime live capture service (arkime-live) in Malcolm runs with network_mode: host, exposing port 8005 on all network interfaces (viewHost=0.0.0.0). Arkime trusts the X-Forwarded-User header from any IP address (userAuthIps=::,0.0.0.0/0) and auto-creates users with full access. The passwordSecret is hardcoded to the public value "Malcolm". A network-adjacent attacker bypasses nginx entirely by connecting directly to port 8005 with a forged identity header.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
