Origin validation error in nginx-ui - #VU152970
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass IP allowlist enforcement.
The vulnerability exists due to origin validation error in the bundled reverse-proxy client identity handling when forwarding management API requests. A remote attacker can send requests through the bundled proxy to bypass IP allowlist enforcement.
Protected management operations still require valid credentials.