PT-2026-47446 · Unknown · Nginx Proxy Manager

·

CVE-2026-40519

·

Published

2026-06-08

·

Updated

2026-07-23

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nginx Proxy Manager versions 2.9.14 through 2.15.1
Description An authenticated remote code execution issue exists via OS command injection in the setupCertbotPlugins() function located in backend/setup.js. Attackers with certificates:manage permissions can execute arbitrary commands by storing a malicious payload in the dns provider credentials field. This occurs because the user-controlled dns provider credentials value is interpolated directly into a shell command executed via child process.exec() without proper sanitization or escaping, leading to command execution upon backend restart. Real-world offensive activities targeting this issue have been identified.
Recommendations Update Nginx Proxy Manager to a version that includes commit a5db5ed. Restrict access to the dns provider credentials field to minimize the risk of exploitation.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40519

Affected Products

Nginx Proxy Manager