Malcolm's nginx Lua role-based access control (RBAC)...
Moderate severity
Unreviewed
Published
Aug 18, 2026
to the GitHub Advisory Database
•
Updated Aug 18, 2026
Description
Published by the National Vulnerability Database
Aug 18, 2026
Published to the GitHub Advisory Database
Aug 18, 2026
Last updated
Aug 18, 2026
Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /auth, /admin_login, /arkime/api/esadmin, NetBox, upload endpoints) by pattern-matching the raw, percent-encoded request URI. Nginx itself, however, selects which location block actually serves the request using the percent-decoded, normalized URI. Because the RBAC check never percent-decodes its input, an authenticated low-privilege user can request an admin-only path using percent-encoding (e.g. /%68tadmin.php) and have nginx route it to the restricted location while the Lua RBAC gate evaluating the un-decoded raw string finds no matching restriction and grants access.
References