Improper access control in nginx-ui - #VU142600

 

Improper access control in nginx-ui - #VU142600

Published: August 14, 2026


Vulnerability identifier: #VU142600
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary OS commands.

The vulnerability exists due to improper access control in the POST /api/restore endpoint and backup restore flow when restoring a crafted backup file. A remote privileged user can upload a crafted backup that overwrites app.ini and then trigger nginx control functionality to execute arbitrary OS commands.

The issue bypasses protected settings controls by writing configuration directly to disk, and the restored application configuration is loaded after an automatic restart.


Affected software

nginx-ui

Remediation

Install security update from vendor's website.

nginx-ui - update to 2.5.0

External References

Related Security Bulletins