Authorization Bypass in NGINX JavaScript and QuickJS Engines
CVE-2026-18329

8.8HIGH

Key Information:

Vendor

F5

Vendor
CVE Published:
2 September 2026

What is CVE-2026-18329?

A vulnerability exists in the NGINX JavaScript (njs) and QuickJS (qjs) engines, which affects the js_access handler when it processes asynchronous request body handling. If an exception occurs during the asynchronous access-control evaluation prior to an explicit access denial, unauthenticated attackers can exploit this flaw. By sending crafted HTTP requests that trigger error conditions in the access validation logic, attackers can bypass js_access controls. This results in potential unauthorized access to sensitive resources, posing significant security risks to affected systems.

Affected Version(s)

NGINX JavaScript 1.0.0 < 1.0.1

NGINX JavaScript 0.9.9

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

F5 acknowledges Ta Duc Thien (@thientd) of NTCS for bringing this issue to our attention and following the highest standards of coordinated disclosure.
.