Improper Verification of Cryptographic Signature in nginx-ui - #VU142599

 

Improper Verification of Cryptographic Signature in nginx-ui - #VU142599

Published: August 14, 2026


Vulnerability identifier: #VU142599
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code as root.

The vulnerability exists due to improper verification of cryptographic signature in the backup restore mechanism when processing a crafted backup bundle. A remote user can upload a crafted backup archive that overwrites app.ini and then access the /api/pty terminal endpoint to execute arbitrary code as root.

No administrator interaction is required beyond the attacker\'s own session. In the official Docker image, the spawned shell runs with root privileges.


Affected software

nginx-ui

Remediation

Install security update from vendor's website.

nginx-ui - update to 2.5.0

External References

Related Security Bulletins