Nginx UI 是 Nginx Web 服务器的一个基于 Web 的管理界面。在版本 2.0.0 至 2.5.0 中,前端将 JWT(JSON Web Token)存储在浏览器管理的 Cookie 中后,AuthRequired 会将该 Cookie 作为 API 凭据接受。由于管理端点普遍未要求 CSRF 令牌,也未执行 Origin 或 Referer 头部验证,远程攻击者可诱导已登录管理员的浏览器提交经过身份验证的跨站状态更改请求,例如 POST /api/configs。 该攻击利用前提是目标管理员账户未
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107806 | 9.4 CRITICAL | Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite |
| CVE-2026-107807 | 8.8 HIGH | Nginx UI: Node Secret Credential Exposure via URL Query Parameter |
| CVE-2026-107811 | 8.8 HIGH | 0xJacky/nginx-ui /api/nodes Leaks Cluster Node Tokens and Allows Cross-Node Impersonation |
| CVE-2026-107813 | 8.8 HIGH | Nginx UI: Incomplete fix of CVE-2026-84315 - the api/cluster router was not - wrapped in |
| CVE-2026-107808 | 8.1 HIGH | Nginx UI: Authentication bypass: password login does not enforce a passkey-only second fac |
| CVE-2026-107810 | 8.1 HIGH | Nginx UI: Backup restore follows crafted symlinks into the live Nginx configuration path b |
| CVE-2026-107805 | 7.5 HIGH | Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage |
| CVE-2026-107812 | 7.5 HIGH | Nginx UI: Self-upgrade runs an unsigned binary verified only by a same-origin digest → RCE |
| CVE-2026-107804 | 5.3 MEDIUM | Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout |
No comments yet