Description
Nginx UI is a web user interface for the Nginx web server. From 2.2.0 until 2.6.0, the bundled reverse proxy does not preserve the external client identity used by Gin because the backend has no trusted proxy configuration. Management requests can be attributed to loopback and pass the IP allowlist loopback exception, although valid credentials are still required. Failed logins from different external clients are also attributed to the same loopback address, allowing an unauthenticated attacker to trigger a shared temporary login ban for password or OTP authentication without invalidating existing sessions. This issue is fixed in version 2.6.0.
Published: 2026-10-09
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

Nginx UI’s bundled reverse proxy fails to preserve the external client’s IP address, resulting in requests appearing to originate from the loopback interface. Because the IP allowlist configuration only excludes the loopback interface, an attacker can send management‑related traffic from any external address that is treated as permitted. In addition, authentication failures from distinct external clients are consolidated under the loopback address, allowing an unauthenticated user to provoke a shared temporary login ban for password or OTP authentication. The attacker therefore gains indirect access to bypass IP‑based restrictions and can cause legitimate users to be denied service through lockout.

Affected Systems

The vulnerability is present in the 0xJacky:nginx-ui package, specifically in all releases from version 2.2.0 up to and excluding 2.6.0. Version 2.6.0 introduces the fix that correctly preserves external IP addresses and prevents the shared lockout issue.

Risk and Exploitability

The CVSS score of 5.3 places this issue in the medium severity range. EPSS data is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is remote, as an external adversary can send requests to the management interface from arbitrary IPs and trigger the lockout mechanism without needing initial authentication or valid credentials. Exploitation requires the existence of a working authentication system that logs failure attempts, but the attacker does not need administrative privileges.

Generated by OpenCVE AI on October 9, 2026 at 16:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Nginx UI package to version 2.6.0 or later, which restores proper external IP handling and removes the shared lockout flaw.
  • If upgrading immediately is not possible, restrict management interface access to trusted IP ranges only and remove or deny the loopback exception in the IP allowlist to mitigate bypass risk.
  • Enable auditing or monitoring of authentication failure events to detect any attempts to trigger shared lockout and review session lockout policies to limit the impact to individual user accounts.

Generated by OpenCVE AI on October 9, 2026 at 16:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 09 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
Description Nginx UI is a web user interface for the Nginx web server. From 2.2.0 until 2.6.0, the bundled reverse proxy does not preserve the external client identity used by Gin because the backend has no trusted proxy configuration. Management requests can be attributed to loopback and pass the IP allowlist loopback exception, although valid credentials are still required. Failed logins from different external clients are also attributed to the same loopback address, allowing an unauthenticated attacker to trigger a shared temporary login ban for password or OTP authentication without invalidating existing sessions. This issue is fixed in version 2.6.0.
Title Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout
Weaknesses CWE-346
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T15:09:10.128Z

Reserved: 2026-10-08T21:23:59.820Z

Link: CVE-2026-107804

cve-icon Vulnrichment

Updated: 2026-10-09T15:08:34.739Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-09T15:17:09.750

Modified: 2026-10-09T16:38:57.820

Link: CVE-2026-107804

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T16:30:09Z

Weaknesses