CVE-2026-107336 | CISA Malcolm up to 26.07.1 Nginx Reverse Proxy X-Forwarded-User access control
A vulnerability was found in CISA Malcolm up to 26.07.1. It has been declared as critical. The affected element is an unknown function of the component Nginx Reverse Proxy. Executing a manipulation of the argument X-Forwarded-User can lead to improper access controls.
This vulnerability appears as CVE-2026-107336. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More