Code Injection in nginx-ui - CVE-2026-42238

 

Code Injection in nginx-ui - CVE-2026-42238

Published: July 17, 2026


Vulnerability identifier: #VU138330
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-42238
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper control of code generation in the POST /api/restore endpoint when restoring a crafted backup archive during the unauthenticated installation window after process startup. A remote attacker can upload a crafted backup archive and trigger configuration testing to execute arbitrary code.

The issue is reachable only on fresh installations within 10 minutes of process startup, and the window reopens after each restart. Exploitation also requires the attacker to reach the service from an IP address not blocked by the IP whitelist.


Affected software

nginx-ui

How to mitigate CVE-2026-42238

Install security update from vendor's website.

nginx-ui - update to 2.3.8

External References

Related Security Bulletins