Nginx UI 是 Nginx Web 服务器的 Web 用户界面。在版本 2.0.0 至 2.5.0 中,POST /api/login 接口在检查 EnabledOTP 标志时,若 EnabledPasskey 为 true 且未配置 TOTP 密钥,则不会要求提供 WebAuthn 断言(assertion)。因此,对于仅注册了通行密钥(passkey)的账户,在验证密码后仍会发放会话令牌(session),尽管 Enabled2FA 表明该账户已配置了双因素认证。攻击者在获取密码后,即可接管该账户,并在无
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107806 | 9.4 CRITICAL | Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite |
| CVE-2026-107807 | 8.8 HIGH | Nginx UI: Node Secret Credential Exposure via URL Query Parameter |
| CVE-2026-107809 | 8.8 HIGH | Nginx-UI AuthRequired token cookie fallback enables CSRF against management APIs |
| CVE-2026-107811 | 8.8 HIGH | 0xJacky/nginx-ui /api/nodes Leaks Cluster Node Tokens and Allows Cross-Node Impersonation |
| CVE-2026-107813 | 8.8 HIGH | Nginx UI: Incomplete fix of CVE-2026-84315 - the api/cluster router was not - wrapped in |
| CVE-2026-107810 | 8.1 HIGH | Nginx UI: Backup restore follows crafted symlinks into the live Nginx configuration path b |
| CVE-2026-107805 | 7.5 HIGH | Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage |
| CVE-2026-107812 | 7.5 HIGH | Nginx UI: Self-upgrade runs an unsigned binary verified only by a same-origin digest → RCE |
| CVE-2026-107804 | 5.3 MEDIUM | Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout |
No comments yet