Description
Nginx UI is a web user interface for the Nginx web server. From 2.3.8 until 2.5.0, an authenticated administrator with an active secure session can submit attacker-controlled portable backup key material and a matching manifest to POST /api/restore. The restore flow trusts the supplied key, decrypts attacker-controlled contents, and replaces the live app.ini, including protected nginx command settings such as TestConfigCmd. Triggering POST /api/nginx/test then executes the restored command in the Nginx UI runtime context, affecting confidentiality, integrity, and availability. This issue is fixed in version 2.5.0.
Published: 2026-10-09
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution via authenticated administrator session
Action: Immediate Patch
AI Analysis

Impact

The flaw allows an authenticated administrator to supply malicious backup data that is decrypted and used to overwrite the application configuration file. By restoring a crafted configuration, the attacker can inject arbitrary command strings into protected fields such as TestConfigCmd. Subsequent invocation of the test endpoint executes those commands in the Nginx UI runtime context, giving the attacker full control over the server. This leads to compromise of confidentiality, integrity, and availability (CWE‑94).

Affected Systems

The vulnerability affects the 0xJacky nginx‑ui product in versions 2.3.8 through 2.4.x. All installations running any release from 2.3.8 up to, but not including, 2.5.0 are impacted.

Risk and Exploitability

The CVSS score of 9.4 indicates a critical severity. EPSS is not available, but the attack requires an authenticated administrator session and the ability to send HTTP requests. Since the vulnerability is tied to a specific API endpoint and relies on the application trusting supplied backup data, an attacker would need valid credentials or access to elevated privileges. The issue is not listed in the CISA KEV catalog, suggesting no known exploitation yet. Nonetheless, the combination of remote code execution and ease of exploitation makes the risk high.

Generated by OpenCVE AI on October 9, 2026 at 16:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade nginx‑ui to version 2.5.0 or newer, which contains the fix.
  • If an upgrade is not immediately possible, restrict or disable the /api/restore endpoint for non‑administrator roles and remove the ability for administrators to submit arbitrary backup data.
  • Implement input validation and sanitization for configuration files to prevent command injection, following CWE‑94 best practices.

Generated by OpenCVE AI on October 9, 2026 at 16:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Description Nginx UI is a web user interface for the Nginx web server. From 2.3.8 until 2.5.0, an authenticated administrator with an active secure session can submit attacker-controlled portable backup key material and a matching manifest to POST /api/restore. The restore flow trusts the supplied key, decrypts attacker-controlled contents, and replaces the live app.ini, including protected nginx command settings such as TestConfigCmd. Triggering POST /api/nginx/test then executes the restored command in the Nginx UI runtime context, affecting confidentiality, integrity, and availability. This issue is fixed in version 2.5.0.
Title Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T15:00:55.470Z

Reserved: 2026-10-08T21:23:59.820Z

Link: CVE-2026-107806

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-09T15:17:10.150

Modified: 2026-10-09T16:38:57.820

Link: CVE-2026-107806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T16:30:09Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')