Nginx UI 是 Nginx Web 服务器的 Web 用户界面。在版本 2.0.0 至 2.5.0 之间, 模块会在应用 和 标志之前解包内部归档文件,并允许包含指向当前 Nginx 配置路径的符号链接。即使 和 标志均为 false,具有创建和恢复备份权限的认证用户仍可构造一个有效的备份,在临时目录(staging tree)中放置符号链接,并通过该链接写入常规文件。随后,当这些被篡改的文件被 Nginx 消费时,可能导致持久化的配置注入或服务拒绝(Denial of Service)。该问题已在版本 2.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107806 | 9.4 CRITICAL | Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite |
| CVE-2026-107807 | 8.8 HIGH | Nginx UI: Node Secret Credential Exposure via URL Query Parameter |
| CVE-2026-107809 | 8.8 HIGH | Nginx-UI AuthRequired token cookie fallback enables CSRF against management APIs |
| CVE-2026-107811 | 8.8 HIGH | 0xJacky/nginx-ui /api/nodes Leaks Cluster Node Tokens and Allows Cross-Node Impersonation |
| CVE-2026-107813 | 8.8 HIGH | Nginx UI: Incomplete fix of CVE-2026-84315 - the api/cluster router was not - wrapped in |
| CVE-2026-107808 | 8.1 HIGH | Nginx UI: Authentication bypass: password login does not enforce a passkey-only second fac |
| CVE-2026-107805 | 7.5 HIGH | Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage |
| CVE-2026-107812 | 7.5 HIGH | Nginx UI: Self-upgrade runs an unsigned binary verified only by a same-origin digest → RCE |
| CVE-2026-107804 | 5.3 MEDIUM | Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout |
No comments yet