Link following in nginx-ui - #VU142598
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to modify the live Nginx configuration path.
The vulnerability exists due to improper link resolution before file access in the backup restore process when extracting crafted backup archives. A remote user can create and restore a crafted backup archive to modify the live Nginx configuration path.
The issue is triggered before the restore flags are applied, so files can be written into the live configuration tree even when both restore options are set to false.