Description
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster router exposes node and namespace mutation operations and cluster-wide Nginx reload or restart operations with AuthRequired but without RequireSecureSession. An authenticated OTP-enabled user possessing a stolen or persisted JWT can therefore perform node CRUD, read or replace node credentials, change namespaces, and invoke nodes/reload_nginx or nodes/restart_nginx without a fresh second-factor step-up. This issue is an incomplete fix for CVE-2026-84315 and is fixed in version 2.5.0.
Published: 2026-10-09
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation via Unauthorized API Operations
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Nginx UI allows an authenticated user with a stolen or persisted JWT to perform full node and namespace management operations, as well as trigger cluster‑wide reload or restart actions, without the required OTP step‑up. This missing second‑factor enforcement (RequireSecureSession) enables the attacker to execute sensitive mutations that normally trigger multi‑factor authentication, thereby escalating privileges and potentially disrupting service availability or executing arbitrary configuration changes on the Nginx instance.

Affected Systems

Product: Nginx UI by 0xJacky. The issue exists in all releases from 2.0.0 up to, but not including, 2.5.0. Upgrades to 2.5.0 and later resolve the problem.

Risk and Exploitability

The CVSS score of 8.8 indicates a high‑severity flaw, and while the EPSS score is not available, the absence of a KEV listing does not reduce the risk. An attacker can exploit the flaw remotely through the web API once a valid JWT is obtained, and the lack of a second‑factor check eliminates an important layer of defense. The vulnerability is listed as an incomplete fix of CVE‑2026‑84315, highlighting the critical need to apply the latest patch or otherwise enforce OTP enforcement on the affected routes.

Generated by OpenCVE AI on October 9, 2026 at 17:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Nginx UI v2.5.0 or later, where the api/cluster router is protected with RequireSecureSession.
  • Revoke any JWT tokens that may have been compromised and require users to re‑authenticate with OTP.
  • If an upgrade is not immediately possible, manually enable RequireSecureSession for the /api/cluster routes in the application configuration to restore OTP enforcement for all privileged operations.

Generated by OpenCVE AI on October 9, 2026 at 17:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-h246-wpgf-vmq5 Nginx UI: Incomplete fix of CVE-2026-84315 - the api/cluster router was not - wrapped in RequireSecureSession, so those sensitive mutations run without OTP step-up
History

Fri, 09 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 09 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared 0xjacky
0xjacky nginx-ui
Vendors & Products 0xjacky
0xjacky nginx-ui

Fri, 09 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster router exposes node and namespace mutation operations and cluster-wide Nginx reload or restart operations with AuthRequired but without RequireSecureSession. An authenticated OTP-enabled user possessing a stolen or persisted JWT can therefore perform node CRUD, read or replace node credentials, change namespaces, and invoke nodes/reload_nginx or nodes/restart_nginx without a fresh second-factor step-up. This issue is an incomplete fix for CVE-2026-84315 and is fixed in version 2.5.0.
Title Nginx UI: Incomplete fix of CVE-2026-84315 - the api/cluster router was not - wrapped in RequireSecureSession, so those sensitive mutations run without OTP step-up
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

0xjacky Nginx-ui
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T17:16:22.934Z

Reserved: 2026-10-08T21:23:59.822Z

Link: CVE-2026-107813

cve-icon Vulnrichment

Updated: 2026-10-09T17:14:29.051Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-10-09T16:17:26.007

Modified: 2026-10-09T18:17:02.927

Link: CVE-2026-107813

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T17:30:08Z

Weaknesses