Missing Authorization in nginx-ui - #VU152976
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to obtain persistent administrator access.
The vulnerability exists due to missing authorization in user-management mutation routes when processing requests authenticated with a valid write-scoped service token. A remote user can create or alter an enabled administrator account to obtain persistent administrator access.
Read-only service tokens cannot reach the affected user-mutation operations.