Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-107806: Nginx UI admin can run arbitrary commands via backup restore

CVE-2026-107806 · published 1 day ago
Summary

Versions 2.3.8 through 2.5.0 of Nginx UI let a logged‑in administrator upload a specially crafted backup file that replaces the program’s configuration and then runs the attacker’s command. This can let an attacker read, change or stop your web service. Upgrade to version 2.5.0 or newer to close the problem.

What to do
  • Update github.com 0xjacky to version 1.9.10-0.20260728074146-a467ed652591.
  • Update 0xjacky github.com/0xjacky/nginx-ui to version 1.9.10-0.20260728074146-a467ed652591.
Affected software
Ecosystem VendorProductAffected versions
– 0xjacky nginx-ui >= 2.3.8, < 2.5.0
go github.com 0xjacky >= 1.9.10-0.20260421071512-7864e378f5cf, < 1.9.10-0.20260728074146-a467ed652591
Fix: upgrade to 1.9.10-0.20260728074146-a467ed652591
Go 0xjacky github.com/0xjacky/nginx-ui >= 1.9.10-0.20260421071512-7864e378f5cf, < 1.9.10-0.20260728074146-a467ed652591
Fix: upgrade to 1.9.10-0.20260728074146-a467ed652591
Original advisory text
Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite
Nginx UI is a web user interface for the Nginx web server. From 2.3.8 until 2.5.0, an authenticated administrator with an active secure session can submit attacker-controlled portable backup key material and a matching manifest to POST /api/restore. The restore flow trusts the supplied key, decrypts attacker-controlled contents, and replaces the live app.ini, including protected nginx command settings such as TestConfigCmd. Triggering POST /api/nginx/test then executes the restored command in the Nginx UI runtime context, affecting confidentiality, integrity, and availability. This issue is fixed in version 2.5.0.
Severity
9.4 Critical
Type
CWE-94Code Injection
Timeline
Published9 Oct 2026
Updated10 Oct 2026
First seen9 Oct 2026
Track software like this
Free during beta