Improper Authorization in Nginx Proxy Manager Allows Configuration Injection
CVE-2026-102335
7.1HIGH
What is CVE-2026-102335?
Nginx Proxy Manager versions up to 2.16.0 contain a vulnerability that allows non-admin users with manage permissions to access the advanced_config field. This oversight enables these users to inject arbitrary nginx directives, potentially leading to unauthorized file serving or manipulation of routing for their designated hosts. It is crucial for users to implement proper access controls to mitigate these risks and protect the integrity of their server configurations.
Affected Version(s)
nginx-proxy-manager 0 <= 2.16.0
