Nginx UI是Jacky个人开发者的一个 Nginx 的 WebUI。 Nginx UI 2.0.0版本至2.3.8之前版本存在访问控制错误漏洞,该漏洞源于首次运行设置期间公共/api/install端点无需认证,可能导致未认证网络攻击者声明初始管理员账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Nginx UI 2.0.0 to 2.3.8 contains an authentication bypass caused by unauthenticated access to /api/install during first-run setup, letting remote attackers claim the initial admin account, exploit requires attacker to access the service before legitimate operator. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-42221.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-42222 | 8.1 HIGH | nginx-ui: Unauthenticated first-boot instance claim via POST /api/install allows remote bo |
| CVE-2026-42220 | 6.5 MEDIUM | nginx-ui: Authenticated settings disclosure exposes node.secret and enables trusted-node a |
| CVE-2026-42223 | 6.5 MEDIUM | nginx-ui: Settings API Exposes Protected Secrets |
| CVE-2026-42238 | Unauthenticated Remote Code Execution via Backup Restore in nginx-ui |
No comments yet