Injection Vulnerability in NGINX Ingress Controller by F5 Networks
CVE-2026-77180

8.7HIGH

Key Information:

Vendor

F5

Vendor
CVE Published:
2 September 2026

What is CVE-2026-77180?

An injection vulnerability has been identified in the configuration generator of the NGINX Ingress Controller. When configured with specific annotations, an attacker with write permissions can manipulate the NGINX configuration by injecting arbitrary directives. This poses a significant risk, as malicious alterations can lead to unauthorized actions including file creation or deletion and service disruptions. While this vulnerability affects the control plane, it does not expose data in the data plane.

Affected Version(s)

NGINX Ingress Controller 5.0.0 < 5.6.0

NGINX Ingress Controller 2026-lts-r1 < 2026-lts-r5

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

F5 acknowledges kodareef5 for bringing this issue to our attention and following the highest standards of coordinated disclosure.
.