OS Command Injection in nginx-ui - #VU142595
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary commands.
The vulnerability exists due to improper neutralization of special elements used in an os command in the backup restore handler and settings-driven command execution sinks when restoring a crafted backup containing attacker-controlled app.ini settings. A remote user can upload a crafted backup file to overwrite command execution settings and execute arbitrary commands.
The logrotate command sink may be triggered automatically by the scheduled interval, enabling persistent execution without further user interaction. The issue can also be reached during the setup window through the restore endpoint that requires only the install secret.