Nginx UI 是 Nginx Web 服务器的 Web 用户界面。在版本 2.2.0 到 2.6.0 之间,内置的反向代理未能保留 Gin 框架所需的客户端外部身份标识,因为后端未配置可信代理。这导致管理请求被归因于本地回环地址(loopback),从而绕过了 IP 白名单中的回环例外规则。尽管攻击者仍需有效的凭据才能成功登录,但来自不同外部客户端的失败登录尝试均被记录为同一个回环地址。这使得未经身份验证的攻击者可以触发针对密码或 OTP(一次性密码)认证的共享临时登录禁令,而不会影响其他已建立会话的有效性。该
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107806 | 9.4 CRITICAL | Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite |
| CVE-2026-107807 | 8.8 HIGH | Nginx UI: Node Secret Credential Exposure via URL Query Parameter |
| CVE-2026-107809 | 8.8 HIGH | Nginx-UI AuthRequired token cookie fallback enables CSRF against management APIs |
| CVE-2026-107811 | 8.8 HIGH | 0xJacky/nginx-ui /api/nodes Leaks Cluster Node Tokens and Allows Cross-Node Impersonation |
| CVE-2026-107813 | 8.8 HIGH | Nginx UI: Incomplete fix of CVE-2026-84315 - the api/cluster router was not - wrapped in |
| CVE-2026-107808 | 8.1 HIGH | Nginx UI: Authentication bypass: password login does not enforce a passkey-only second fac |
| CVE-2026-107810 | 8.1 HIGH | Nginx UI: Backup restore follows crafted symlinks into the live Nginx configuration path b |
| CVE-2026-107805 | 7.5 HIGH | Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage |
| CVE-2026-107812 | 7.5 HIGH | Nginx UI: Self-upgrade runs an unsigned binary verified only by a same-origin digest → RCE |
No comments yet