Information disclosure in nginx-ui - #VU142590
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in the /api/nodes and /api/nodes/:id cluster node endpoints when handling authenticated API requests. A remote user can request node list or detail responses to disclose sensitive information.
Exploitation requires a valid low-privileged user account and at least one configured cluster node.