SB2026090747 - Configuration injection in F5 NGINX Gateway Fabric
Published: September 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Neutralization of Equivalent Special Elements (CVE-ID: CVE-2026-66362)
CWE-ID: CWE-76 - Improper Neutralization of Equivalent Special Elements
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to inject arbitrary NGINX configuration directives.
The vulnerability exists due to improper neutralization of special elements in the NGINX configuration generator when rendering user-supplied AuthenticationFilter CRD values and referenced secret values into NGINX configuration templates. A remote user can create or modify AuthenticationFilter CRD resources or their referenced secrets to inject arbitrary NGINX configuration directives.
Exploitation requires NGINX Plus to be configured as the data plane and affects the control plane only; there is no data plane exposure.
Remediation
Install update from vendor's website.