Cross-site request forgery in nginx-ui - #VU142587
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform cross-site request forgery against management APIs.
The vulnerability exists due to cross-site request forgery in the AuthRequired authentication middleware when handling cross-site state-changing requests from a logged-in administrator\'s browser. A remote attacker can induce the victim to submit a specially crafted request to perform cross-site request forgery against management APIs.
User interaction is required, and exploitation requires a logged-in administrator\'s browser to carry the token cookie. Accounts without OTP or Passkey, or endpoints that do not require secure-session proof, are affected.