Missing Authorization in nginx-ui - #VU142602

 

Missing Authorization in nginx-ui - #VU142602

Published: August 14, 2026


Vulnerability identifier: #VU142602
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to send a fixed-format outbound POST request and obtain limited status and timing information.

The vulnerability exists due to improper access control in the external notification test endpoint when handling authenticated notification test requests without interactive secure-session enforcement. A remote user can trigger a notification test request to a caller-supplied endpoint to send a fixed-format outbound POST request and obtain limited status and timing information.

The target response body is not returned, credentials are not forwarded, and the caller cannot choose an arbitrary HTTP method or arbitrary request body.


Affected software

nginx-ui

Remediation

Install security update from vendor's website.

nginx-ui - update to 2.5.7

External References

Related Security Bulletins