Nginx UI Vulnerability Exposes Node and Namespace Operations by Authenticated Users
CVE-2026-107813
8.8HIGH
What is CVE-2026-107813?
The Nginx UI web interface has a vulnerability allowing authenticated users with one-time password (OTP) capabilities to misuse their access. Specifically, between versions 2.0.0 and 2.5.0, the api/cluster router enables node and namespace modifications as well as cluster-wide Nginx reload or restart actions. The problem lies in the inadequate session protection, which permits an attacker with a stolen JSON Web Token (JWT) to perform critical operations without requiring a new second-factor authentication step. This lack of secure session enforcement stems from an incomplete remediation of a previous vulnerability. Users are urged to update to version 2.5.0 where this issue has been addressed.
Affected Version(s)
nginx-ui >= 2.0.0, < 2.5.0
