Arbitrary Command Execution in Nginx UI Web Interface by Nginx
CVE-2026-107806

9.4CRITICAL

Key Information:

Vendor

0xjacky

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107806?

An issue in the Nginx UI web user interface permits an authenticated administrator to exploit backup key material submission. This occurs from versions 2.3.8 to 2.5.0, enabling attackers to manipulate the restore flow. When compromised key material and manifest are provided, the system untrustingly decrypts the contents and overwrites the live app.ini file, leading to unauthorized execution of commands in the Nginx environment. This creates significant risks to system confidentiality, integrity, and overall availability of services. The vulnerability is addressed in Nginx UI version 2.5.0.

Affected Version(s)

nginx-ui >= 2.3.8, < 2.5.0

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.