Remote Code Execution Vulnerability in Nginx UI by 0xJacky
CVE-2026-107812
7.5HIGH
What is CVE-2026-107812?
Nginx UI, the web user interface for the Nginx web server, experienced a vulnerability in its self-upgrade mechanism prior to version 2.5.0. This flaw allows a potential attacker with control over the upgrade mirror or network to deliver a malicious executable, along with a matching digest, which can compromise the system during an operator-initiated upgrade. The application would subsequently execute the attacker-controlled code in the context of the Nginx UI process, posing significant security risks. Users are strongly advised to upgrade to version 2.5.0 or later to mitigate this vulnerability.
Affected Version(s)
nginx-ui >= 2.0.0, < 2.5.0
