PT-2026-36920 · Nginx-Ui · Nginx-Ui

·

CVE-2026-42220

·

Published

2026-04-21

·

Updated

2026-07-30

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nginx UI versions prior to 2.3.8
Description An authenticated user can access the 'GET /api/settings' endpoint to retrieve sensitive configuration values, such as node.secret. This secret is accepted by the AuthRequired() function via the 'X-Node-Secret' header or the node secret query parameter, allowing requests to be treated as authenticated through the trusted-node path and associated with the init user.
Recommendations Update to version 2.3.8.

Exploit

Fix

Incorrect Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06342
CVE-2026-42220
GHSA-7JRR-XW9C-MJ39
GO-2026-5227
OPENSUSE-SU-2026:21483-1

Affected Products

Nginx-Ui