Description
A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Monitor
AI Analysis

Impact

This vulnerability arises in the /adminPage/main/autoUpdate endpoint of cym1102 nginxWebUI. By manipulating the url parameter, an attacker can inject arbitrary code into the autoUpdate method, leading to remote code execution on the web server. The weakness maps to CWE-74 and CWE-94.

Affected Systems

vulnerable versions of cym1102 nginxWebUI up to 4.4.2 are affected. No later versions have been identified as impacted. The problem exists in the open source project hosted at the specifiedHub repository.

Risk and Exploitability

The CVSS base score of 5.3 indicates medium severity. The EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog. Remote exploitation is possible; the publicly disclosed exploit confirms that code injection can be achieved through the autoUpdate endpoint. Until a patch is merged, the technical feasibility and medium risk warrant monitoring and mitigation steps.

Generated by OpenCVE AI on September 15, 2026 at 17:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the pending patch after a pull request is merged by reviewing the fix and deploying it to all affected instances
  • Disable or block remote access to the /adminPage/main/autoUpdate URL and/or the entire adminPage until the fix is appliedWebUI admin interface to trusted IP addresses, enforce strong authentication, and consider mitigating inbound requests with a web application firewall
  • Configure the web application firewall to block suspicious script payloads in the url parameter

Generated by OpenCVE AI on September 15, 2026 at 17:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
Title cym1102 nginxWebUI autoUpdate MainController.autoUpdate code injection
First Time appeared Cym1102
Cym1102 nginxwebui
Weaknesses CWE-74
CWE-94
CPEs cpe:2.3:a:cym1102:nginxwebui:*:*:*:*:*:*:*:*
Vendors & Products Cym1102
Cym1102 nginxwebui
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Cym1102 Nginxwebui
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T15:23:41.113Z

Reserved: 2026-09-12T16:44:07.221Z

Link: CVE-2026-90581

cve-icon Vulnrichment

Updated: 2026-09-14T15:23:35.948Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T20:16:51.487

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90581

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:15:14Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')