Injection Vulnerability in NGINX Ingress Controller by F5 Networks
CVE-2026-77180
8.7HIGH
What is CVE-2026-77180?
An injection vulnerability has been identified in the configuration generator of the NGINX Ingress Controller. When configured with specific annotations, an attacker with write permissions can manipulate the NGINX configuration by injecting arbitrary directives. This poses a significant risk, as malicious alterations can lead to unauthorized actions including file creation or deletion and service disruptions. While this vulnerability affects the control plane, it does not expose data in the data plane.
Affected Version(s)
NGINX Ingress Controller 5.0.0 < 5.6.0
NGINX Ingress Controller 2026-lts-r1 < 2026-lts-r5
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
F5 acknowledges kodareef5 for bringing this issue to our attention and following the highest standards of coordinated disclosure.