Improper Neutralization of Equivalent Special Elements in NGINX Gateway Fabric - CVE-2026-66362

 

Improper Neutralization of Equivalent Special Elements in NGINX Gateway Fabric - CVE-2026-66362

Published: September 7, 2026


Vulnerability identifier: #VU147234
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-66362
CWE-ID: CWE-76
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to inject arbitrary NGINX configuration directives.

The vulnerability exists due to improper neutralization of special elements in the NGINX configuration generator when rendering user-supplied AuthenticationFilter CRD values and referenced secret values into NGINX configuration templates. A remote user can create or modify AuthenticationFilter CRD resources or their referenced secrets to inject arbitrary NGINX configuration directives.

Exploitation requires NGINX Plus to be configured as the data plane and affects the control plane only; there is no data plane exposure.


Affected software

NGINX Gateway Fabric

How to mitigate CVE-2026-66362

Install security update from vendor's website.

NGINX Gateway Fabric - update to 2.6.8

External References

Related Security Bulletins