PT-2026-90953 · Cym1102+1 · Nginxwebui

·

CVE-2026-90581

·

Published

2026-09-13

·

Updated

2026-09-14

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions cym1102 nginxWebUI versions prior to 4.4.3
Description Remote code injection is possible through the manipulation of the url argument within the MainController.autoUpdate() function located in the /adminPage/main/autoUpdate file.
Recommendations As a temporary workaround, restrict access to the /adminPage/main/autoUpdate endpoint or disable the MainController.autoUpdate() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90581

Affected Products

Nginxwebui