PT-2026-108935 · Nginx-Ui · Nginx-Ui
CVE-2026-107806
·
Published
2026-10-09
·
Updated
2026-10-10
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Nginx UI versions 2.3.8 through 2.4.x
Description
An authenticated administrator with an active secure session can submit attacker-controlled portable backup key material and a matching manifest to the 'POST /api/restore' endpoint. The restore process trusts the provided key and decrypts attacker-controlled contents, which replaces the live
app.ini file, including protected nginx command settings such as TestConfigCmd. Subsequently, triggering the 'POST /api/nginx/test' endpoint executes the restored command within the Nginx UI runtime context, impacting confidentiality, integrity, and availability.Recommendations
Update to version 2.5.0.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nginx-Ui