Unauthenticated Network Access in Nginx UI Web Interface
CVE-2026-42221
8.1HIGH
What is CVE-2026-42221?
An unauthenticated network attacker can exploit a flaw in Nginx UI's setup process, allowing them to seize control of the initial administrator account without any form of authentication. By accessing the publicly exposed /api/install endpoint, an unauthorized user can configure the admin email, username, and password before the legitimate user can complete the setup. This vulnerability affects Nginx UI versions from 2.0.0 up to, but not including, 2.3.8 and has been addressed in version 2.3.8.
Affected Version(s)
nginx-ui >= 2.0.0, < 2.3.8
