Impact
The vulnerability in Nginx UI allows an authenticated user with a stolen or persisted JWT to perform full node and namespace management operations, as well as trigger cluster‑wide reload or restart actions, without the required OTP step‑up. This missing second‑factor enforcement (RequireSecureSession) enables the attacker to execute sensitive mutations that normally trigger multi‑factor authentication, thereby escalating privileges and potentially disrupting service availability or executing arbitrary configuration changes on the Nginx instance.
Affected Systems
Product: Nginx UI by 0xJacky. The issue exists in all releases from 2.0.0 up to, but not including, 2.5.0. Upgrades to 2.5.0 and later resolve the problem.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity flaw, and while the EPSS score is not available, the absence of a KEV listing does not reduce the risk. An attacker can exploit the flaw remotely through the web API once a valid JWT is obtained, and the lack of a second‑factor check eliminates an important layer of defense. The vulnerability is listed as an incomplete fix of CVE‑2026‑84315, highlighting the critical need to apply the latest patch or otherwise enforce OTP enforcement on the affected routes.
OpenCVE Enrichment
Github GHSA