Remote Code Execution Vulnerability in Nginx UI by 0xJacky
CVE-2026-107812

7.5HIGH

Key Information:

Vendor

0xjacky

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107812?

Nginx UI, the web user interface for the Nginx web server, experienced a vulnerability in its self-upgrade mechanism prior to version 2.5.0. This flaw allows a potential attacker with control over the upgrade mirror or network to deliver a malicious executable, along with a matching digest, which can compromise the system during an operator-initiated upgrade. The application would subsequently execute the attacker-controlled code in the context of the Nginx UI process, posing significant security risks. Users are strongly advised to upgrade to version 2.5.0 or later to mitigate this vulnerability.

Affected Version(s)

nginx-ui >= 2.0.0, < 2.5.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.