
Critical flaw in Nginx UI (0xJacky): CVE-2026-107806, CVSS 9.4. Versions 2.3.8 up to 2.5.0 let an authenticated admin overwrite the config through the restore endpoint and run commands. VulnTracker recommends upgrading to Nginx UI 2.5.0 or later. Details: http://vulntracker.io/cves/CVE-2026-107806 #NginxUI #CVE #InfoSec




