Authentication bypass using an alternate path or channel in nginx-ui - #VU142584
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to bypass the secure-session step-up requirement and modify Nginx configuration.
The vulnerability exists due to authentication bypass using an alternate path or channel in the /mcp and /mcp_message MCP endpoints when handling configuration mutation requests. A remote user can use the nginx_config_add or nginx_config_modify tools through the MCP interface to bypass the secure-session step-up requirement and modify Nginx configuration.
Only OTP-enabled accounts are affected, and exploitation requires the MCP feature to be enabled.