Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-107806: Nginx UI admin can run arbitrary commands via backup restore
CVE-2026-107806 · published 1 day ago
Summary
Versions 2.3.8 through 2.5.0 of Nginx UI let a logged‑in administrator upload a specially crafted backup file that replaces the program’s configuration and then runs the attacker’s command. This can let an attacker read, change or stop your web service. Upgrade to version 2.5.0 or newer to close the problem.
What to do
- Update github.com 0xjacky to version 1.9.10-0.20260728074146-a467ed652591.
- Update 0xjacky github.com/0xjacky/nginx-ui to version 1.9.10-0.20260728074146-a467ed652591.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | 0xjacky | nginx-ui | >= 2.3.8, < 2.5.0 |
| go | github.com | 0xjacky |
>= 1.9.10-0.20260421071512-7864e378f5cf, < 1.9.10-0.20260728074146-a467ed652591 Fix: upgrade to 1.9.10-0.20260728074146-a467ed652591
|
| Go | 0xjacky | github.com/0xjacky/nginx-ui |
>= 1.9.10-0.20260421071512-7864e378f5cf, < 1.9.10-0.20260728074146-a467ed652591 Fix: upgrade to 1.9.10-0.20260728074146-a467ed652591
|
Original advisory text
Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite
Nginx UI is a web user interface for the Nginx web server. From 2.3.8 until 2.5.0, an authenticated administrator with an active secure session can submit attacker-controlled portable backup key material and a matching manifest to POST /api/restore. The restore flow trusts the supplied key, decrypts attacker-controlled contents, and replaces the live app.ini, including protected nginx command settings such as TestConfigCmd. Triggering POST /api/nginx/test then executes the restored command in the Nginx UI runtime context, affecting confidentiality, integrity, and availability. This issue is fixed in version 2.5.0.
References
- https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-p393-cf76-4jmr Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-107806 Vendor Advisory
- https://github.com/advisories/GHSA-p393-cf76-4jmr
- https://github.com/0xJacky/nginx-ui Product
- https://github.com/0xJacky/nginx-ui/commit/a467ed652591fc0cd1b466a1ec751b493faef... Patch
- https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.0 URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-1078... Vendor Advisory
Severity
9.4
Critical
Type
CWE-94Code Injection
Timeline
Published9 Oct 2026
Updated10 Oct 2026
First seen9 Oct 2026
Sources
CVE-2026-107806 · NVD
CVE-2026-107806 · MITRE
GHSA-p393-cf76-4jmr · GHSA
GHSA-p393-cf76-4jmr · OSV
CVE-2026-107806 · OSV
Track software like this
Free during beta