Insufficient Session Expiration in nginx-ui - #VU142583
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to regain access using a previously revoked short token.
The vulnerability exists due to insufficient session expiration in short-token cache handling when processing short-token authentication after an account is re-enabled. A remote user can reuse a previously revoked short token to regain access using a previously revoked short token.
This affects standalone short tokens used for WebSocket and explicit-token authentication, and exploitation requires the account to be re-enabled before the cached token entry expires.