Access Control Flaw in Nginx Proxy Manager 2.14.0
CVE-2026-50892
6.5MEDIUM
What is CVE-2026-50892?
An access control vulnerability in the 'Let's Encrypt' certificate download endpoint of Nginx Proxy Manager version 2.14.0 allows authenticated attackers to exploit the system. By sending a specially crafted GET request, the flaw can lead to the unauthorized exposure of TLS private key material, placing sensitive data at risk and potentially compromising secure communications.
