Impact
A flaw in the internalCertificate.validate function of NginxProxyManager allows an unauthenticated attacker to submit arbitrary certificates. The endpoint processes the certificate with OpenSSL but omits authentication checks, creating an opportunity for remote exploitation. The flaw does not leak stored data; the primary risk stems from the uncontrolled OpenSSL processing of attacker-supplied input.
Affected Systems
The vulnerability affects installations of NginxProxyManager up to version 2.15.1. All users running this product or earlier versions are at risk. The attack targets the backend internal/certificate.js route that is exposed to clients.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the attack vector is remote unauthenticated. Although EPSS data is missing, the vulnerability is publicly exploited, implying a realistic threat. The lack of authentication makes it easy for attackers to reach the affected endpoint from anywhere, potentially exploiting the uncontrolled OpenSSL processing of attacker input. The vulnerability is not yet listed in CISA’s KEV catalog.
OpenCVE Enrichment