Path traversal in nginx-ui - #VU142580

 

Path traversal in nginx-ui - #VU142580

Published: August 14, 2026


Vulnerability identifier: #VU142580
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to write files outside the intended backup storage directory.

The vulnerability exists due to path traversal in auto-backup filename generation when handling a user-controlled auto-backup name. A remote user can create or modify an auto-backup task with crafted path traversal sequences in the name to write files outside the intended backup storage directory.

For encrypted configuration backups, the adjacent .key file may also be written outside the intended storage directory with the application process privileges.


Affected software

nginx-ui

Remediation

Install security update from vendor's website.

nginx-ui - update to 2.3.11

External References

Related Security Bulletins