Incorrect authorization in nginx-ui - #VU152968
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to access management APIs.
The vulnerability exists due to incorrect authorization in the AuthRequired middleware when handling management HTTP requests. A remote user can present a valid WebSocket short token as an Authorization credential to access management APIs.
Routes protected by RequireSecureSession continue to require fresh OTP or passkey step-up for accounts with two-factor authentication enabled.