Symlink Vulnerability in Nginx UI by Nginx
CVE-2026-107810

8.1HIGH

Key Information:

Vendor

0xjacky

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107810?

The Nginx UI presents a vulnerability that allows authenticated users to exploit its backup and restore functionality. Versions from 2.0.0 to 2.5.0 are affected, enabling a user with backup restoration privileges to create a malicious backup file. This file can include a symlink that targets the live Nginx configuration path. When the backup is processed, it allows the attacker to write regular files through the symlink, potentially leading to unauthorized configuration changes or denial of service. This vulnerability poses a significant risk to Nginx deployments and is addressed in version 2.5.0.

Affected Version(s)

nginx-ui >= 2.0.0, < 2.5.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.