Arbitrary Command Execution in Nginx UI Web Interface by Nginx
CVE-2026-107806
9.4CRITICAL
What is CVE-2026-107806?
An issue in the Nginx UI web user interface permits an authenticated administrator to exploit backup key material submission. This occurs from versions 2.3.8 to 2.5.0, enabling attackers to manipulate the restore flow. When compromised key material and manifest are provided, the system untrustingly decrypts the contents and overwrites the live app.ini file, leading to unauthorized execution of commands in the Nginx environment. This creates significant risks to system confidentiality, integrity, and overall availability of services. The vulnerability is addressed in Nginx UI version 2.5.0.
Affected Version(s)
nginx-ui >= 2.3.8, < 2.5.0
