Link following in nginx-ui - #VU142598

 

Link following in nginx-ui - #VU142598

Published: August 14, 2026


Vulnerability identifier: #VU142598
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify the live Nginx configuration path.

The vulnerability exists due to improper link resolution before file access in the backup restore process when extracting crafted backup archives. A remote user can create and restore a crafted backup archive to modify the live Nginx configuration path.

The issue is triggered before the restore flags are applied, so files can be written into the live configuration tree even when both restore options are set to false.


Affected software

nginx-ui

Remediation

Install security update from vendor's website.

nginx-ui - update to 2.5.0

External References

Related Security Bulletins