PT-2026-108963 · Nginx-Ui · Nginx-Ui
CVE-2026-107809
·
Published
2026-10-09
·
Updated
2026-10-09
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nginx UI versions 2.0.0 through 2.4.x
Description
Nginx UI contains a cross-site request forgery (CSRF) flaw where the
AuthRequired middleware accepts a browser-managed cookie named token as a valid API credential. Because management endpoints do not universally enforce CSRF tokens or perform Origin and Referer validation, a remote attacker can induce a logged-in administrator to submit authenticated state-changing requests. This occurs because the getToken() function falls back to reading the token cookie if no Authorization header or query parameter is present.An attacker can exploit this to perform administrative operations, such as modifying Nginx configurations via the
/api/configs endpoint, triggering server reloads, changing settings, or managing backups. This attack is possible for administrator accounts that have not enabled OTP/Passkey or for endpoints that do not require secure-session proof. While the attacker cannot read the cross-origin response, they can effectively manipulate the server configuration, potentially leading to traffic redirection, reverse proxy tampering, or denial of service.Recommendations
Update Nginx UI to version 2.5.0.
As a temporary mitigation, administrators should enable OTP or Passkey for their accounts to provide a second factor of authentication for state-changing operations.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nginx-Ui