PT-2026-102397 · Unknown · Nginx Proxy Manager

·

CVE-2026-102335

·

Published

2026-09-28

·

Updated

2026-09-30

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nginx Proxy Manager versions prior to 2.16.1
Description Non-administrator users with manage permissions can inject arbitrary nginx directives because the software fails to restrict the advanced config field to administrators. This allows attackers to implement malicious configurations, such as using alias directives to serve arbitrary files or manipulating routing for their assigned hosts.
Recommendations Update to version 2.16.1 or later. Restrict access to the advanced config field to only authorized administrator accounts.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102335

Affected Products

Nginx Proxy Manager