Missing Authentication for Critical Function in nginx-ui - CVE-2026-42222
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to take over the initial installation and gain administrative control of the instance.
The vulnerability exists due to improper access control in the POST /api/install endpoint when handling bootstrap requests during first-run setup. A remote attacker can submit attacker-controlled bootstrap data to take over the initial installation and gain administrative control of the instance.
Exploitation is possible only while the instance is still uninitialized and within the initial 10-minute setup window.