Nginx UI 是 Nginx Web 服务器的 Web 用户界面。从版本 2.0.0 到 2.5.0,其自升级机制仅使用来自同一升级镜像的相同源(same-origin)摘要对下载的二进制文件进行验证。如果升级镜像被攻陷,或网络攻击者能够同时篡改这两个响应,就可以提供恶意可执行文件及其匹配的摘要。该漏洞需要由操作员触发的升级才能生效,并且在下一次升级时,应用程序会在 Nginx UI 进程上下文中安装并执行攻击者控制的代码。此问题已在版本 2.5.0 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107806 | 9.4 CRITICAL | Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite |
| CVE-2026-107807 | 8.8 HIGH | Nginx UI: Node Secret Credential Exposure via URL Query Parameter |
| CVE-2026-107809 | 8.8 HIGH | Nginx-UI AuthRequired token cookie fallback enables CSRF against management APIs |
| CVE-2026-107811 | 8.8 HIGH | 0xJacky/nginx-ui /api/nodes Leaks Cluster Node Tokens and Allows Cross-Node Impersonation |
| CVE-2026-107813 | 8.8 HIGH | Nginx UI: Incomplete fix of CVE-2026-84315 - the api/cluster router was not - wrapped in |
| CVE-2026-107808 | 8.1 HIGH | Nginx UI: Authentication bypass: password login does not enforce a passkey-only second fac |
| CVE-2026-107810 | 8.1 HIGH | Nginx UI: Backup restore follows crafted symlinks into the live Nginx configuration path b |
| CVE-2026-107805 | 7.5 HIGH | Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage |
| CVE-2026-107804 | 5.3 MEDIUM | Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout |
No comments yet