Missing Authentication for Critical Function in nginx-ui - CVE-2026-42222

 

Missing Authentication for Critical Function in nginx-ui - CVE-2026-42222

Published: July 17, 2026


Vulnerability identifier: #VU138333
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-42222
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to take over the initial installation and gain administrative control of the instance.

The vulnerability exists due to improper access control in the POST /api/install endpoint when handling bootstrap requests during first-run setup. A remote attacker can submit attacker-controlled bootstrap data to take over the initial installation and gain administrative control of the instance.

Exploitation is possible only while the instance is still uninitialized and within the initial 10-minute setup window.


Affected software

nginx-ui

How to mitigate CVE-2026-42222

Install security update from vendor's website.

nginx-ui - update to 2.3.6

External References

Related Security Bulletins