Code Injection in nginx-ui - CVE-2026-42238
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper control of code generation in the POST /api/restore endpoint when restoring a crafted backup archive during the unauthenticated installation window after process startup. A remote attacker can upload a crafted backup archive and trigger configuration testing to execute arbitrary code.
The issue is reachable only on fresh installations within 10 minutes of process startup, and the window reopens after each restart. Exploitation also requires the attacker to reach the service from an IP address not blocked by the IP whitelist.