Missing Authorization in nginx-ui - #VU152974
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to disclose stored infrastructure credentials.
The vulnerability exists due to missing authorization in DNS, ACME External Account Binding, and S3-compatible backup configuration read APIs when handling requests authenticated with an api:read service token. A remote user can request configuration responses to disclose stored infrastructure credentials.
The disclosed credentials may be reusable for configured DNS providers, ACME EAB integrations, or S3-compatible storage.