SB20260814130 - Missing Authorization in nginx-ui



SB20260814130 - Missing Authorization in nginx-ui

Published: August 14, 2026

Security Bulletin ID SB20260814130
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to send a fixed-format outbound POST request and obtain limited status and timing information.

The vulnerability exists due to improper access control in the external notification test endpoint when handling authenticated notification test requests without interactive secure-session enforcement. A remote user can trigger a notification test request to a caller-supplied endpoint to send a fixed-format outbound POST request and obtain limited status and timing information.

The target response body is not returned, credentials are not forwarded, and the caller cannot choose an arbitrary HTTP method or arbitrary request body.


Remediation

Install update from vendor's website.