
CVE-2026-102335: Nginx Proxy Manager lets non-admin users inject arbitrary nginx directives. Here's what that means and how to contain it Wednesday.
Signal is active with 2 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their assigned hosts.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

CVE-2026-102335: Nginx Proxy Manager lets non-admin users inject arbitrary nginx directives. Here's what that means and how to contain it Wednesday.

Dangerous text fields (SQL, config DSLs, templates) are shell-equivalent. If a user can write nginx.conf, they own the proxy. Design RBAC accordingly. source: https://nvd.nist.gov/vuln/detail/CVE-2026-102335