PT-2026-108963 · Nginx-Ui · Nginx-Ui

CVE-2026-107809

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nginx UI versions 2.0.0 through 2.4.x
Description Nginx UI contains a cross-site request forgery (CSRF) flaw where the AuthRequired middleware accepts a browser-managed cookie named token as a valid API credential. Because management endpoints do not universally enforce CSRF tokens or perform Origin and Referer validation, a remote attacker can induce a logged-in administrator to submit authenticated state-changing requests. This occurs because the getToken() function falls back to reading the token cookie if no Authorization header or query parameter is present.
An attacker can exploit this to perform administrative operations, such as modifying Nginx configurations via the /api/configs endpoint, triggering server reloads, changing settings, or managing backups. This attack is possible for administrator accounts that have not enabled OTP/Passkey or for endpoints that do not require secure-session proof. While the attacker cannot read the cross-origin response, they can effectively manipulate the server configuration, potentially leading to traffic redirection, reverse proxy tampering, or denial of service.
Recommendations Update Nginx UI to version 2.5.0. As a temporary mitigation, administrators should enable OTP or Passkey for their accounts to provide a second factor of authentication for state-changing operations.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107809
GHSA-33RR-WQ23-G6GG

Affected Products

Nginx-Ui