Improper access control in nginx-ui - #VU142586

 

Improper access control in nginx-ui - #VU142586

Published: August 14, 2026


Vulnerability identifier: #VU142586
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper access control in the AuthRequired() middleware when handling requests with a valid X-Node-Secret header or node_secret query parameter. A remote attacker can send a specially crafted request carrying the node secret to execute arbitrary code.

Requests authenticated in this way are processed as the initial administrator account, and the issue can be used to create an admin user and access the built-in web terminal.


Affected software

nginx-ui

Remediation

Install security update from vendor's website.

nginx-ui - update to 2.5.0

External References

Related Security Bulletins