OS Command Injection in nginx-ui - #VU142595

 

OS Command Injection in nginx-ui - #VU142595

Published: August 14, 2026


Vulnerability identifier: #VU142595
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary commands.

The vulnerability exists due to improper neutralization of special elements used in an os command in the backup restore handler and settings-driven command execution sinks when restoring a crafted backup containing attacker-controlled app.ini settings. A remote user can upload a crafted backup file to overwrite command execution settings and execute arbitrary commands.

The logrotate command sink may be triggered automatically by the scheduled interval, enabling persistent execution without further user interaction. The issue can also be reached during the setup window through the restore endpoint that requires only the install secret.


Affected software

nginx-ui

Remediation

Install security update from vendor's website.

nginx-ui - update to 2.5.0

External References

Related Security Bulletins