SB2026090747 - Configuration injection in F5 NGINX Gateway Fabric



SB2026090747 - Configuration injection in F5 NGINX Gateway Fabric

Published: September 7, 2026

Security Bulletin ID SB2026090747
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Neutralization of Equivalent Special Elements (CVE-ID: CVE-2026-66362)

CWE-ID: CWE-76 - Improper Neutralization of Equivalent Special Elements

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to inject arbitrary NGINX configuration directives.

The vulnerability exists due to improper neutralization of special elements in the NGINX configuration generator when rendering user-supplied AuthenticationFilter CRD values and referenced secret values into NGINX configuration templates. A remote user can create or modify AuthenticationFilter CRD resources or their referenced secrets to inject arbitrary NGINX configuration directives.

Exploitation requires NGINX Plus to be configured as the data plane and affects the control plane only; there is no data plane exposure.


Remediation

Install update from vendor's website.