Nginx UI 是 Nginx Web 服务器的 Web 用户界面。在版本 2.3.8 到 2.5.0 之间,具有有效安全会话的已认证管理员可以向 端点提交由攻击者控制的便携式备份密钥材料及其匹配的清单文件。恢复流程会信任所提交的密钥,解密攻击者控制的內容,并替换掉正在运行的 配置文件,其中包括受保护的 Nginx 命令设置(如 )。随后,触发对 端点的 POST 请求时,将在 Nginx UI 的运行时上下文中执行被恢复的命令,从而导致机密性、完整性和可用性受到影响。该问题已在版本 2.5.0 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107807 | 8.8 HIGH | Nginx UI: Node Secret Credential Exposure via URL Query Parameter |
| CVE-2026-107809 | 8.8 HIGH | Nginx-UI AuthRequired token cookie fallback enables CSRF against management APIs |
| CVE-2026-107811 | 8.8 HIGH | 0xJacky/nginx-ui /api/nodes Leaks Cluster Node Tokens and Allows Cross-Node Impersonation |
| CVE-2026-107813 | 8.8 HIGH | Nginx UI: Incomplete fix of CVE-2026-84315 - the api/cluster router was not - wrapped in |
| CVE-2026-107808 | 8.1 HIGH | Nginx UI: Authentication bypass: password login does not enforce a passkey-only second fac |
| CVE-2026-107810 | 8.1 HIGH | Nginx UI: Backup restore follows crafted symlinks into the live Nginx configuration path b |
| CVE-2026-107805 | 7.5 HIGH | Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage |
| CVE-2026-107812 | 7.5 HIGH | Nginx UI: Self-upgrade runs an unsigned binary verified only by a same-origin digest → RCE |
| CVE-2026-107804 | 5.3 MEDIUM | Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout |
No comments yet