Unauthenticated Network Access in Nginx UI Web Interface
CVE-2026-42221

8.1HIGH

Key Information:

Vendor

0xjacky

Status
Vendor
CVE Published:
4 May 2026

What is CVE-2026-42221?

An unauthenticated network attacker can exploit a flaw in Nginx UI's setup process, allowing them to seize control of the initial administrator account without any form of authentication. By accessing the publicly exposed /api/install endpoint, an unauthorized user can configure the admin email, username, and password before the legitimate user can complete the setup. This vulnerability affects Nginx UI versions from 2.0.0 up to, but not including, 2.3.8 and has been addressed in version 2.3.8.

Affected Version(s)

nginx-ui >= 2.0.0, < 2.3.8

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.