CVE-2026-107806

LOWCVSS 9.4 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Nginx UI is a web user interface for the Nginx web server. From 2.3.8 until 2.5.0, an authenticated administrator with an active secure session can submit attacker-controlled portable backup key material and a matching manifest to POST /api/restore. The restore flow trusts the supplied key, decrypts attacker-controlled contents, and replaces the live app.ini, including protected nginx command settings such as TestConfigCmd. Triggering POST /api/nginx/test then executes the restored command in the Nginx UI runtime context, affecting confidentiality, integrity, and availability. This issue is fixed in version 2.5.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 3 mentions (2026-10-09); latest day: 2
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-10-09: 3Mentions · 2026-10-10: 210-0910-10
Referenced assets5 URLs
Full discourse5 posts
  • VulnTracker@vuln_tracker

    Critical flaw in Nginx UI (0xJacky): CVE-2026-107806, CVSS 9.4. Versions 2.3.8 up to 2.5.0 let an authenticated admin overwrite the config through the restore endpoint and run commands. VulnTracker recommends upgrading to Nginx UI 2.5.0 or later. Details: http://vulntracker.io/cves/CVE-2026-107806 #NginxUI #CVE #InfoSec

    01020163
    807 followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    A critical Nginx UI RCE vulnerability (CVE-2026-107806) is publicly disclosed with PoC exploit code. Admins must patch now to prevent system takeover. #NginxUI #RCE #Vulnerability #CVE2026107806 #CyberSecurity https://securityonline.info/nginx-ui-rce-vulnerability/

    01020389
    13.0K followersView on X
  • mürrez@murrezsec

    🚨 CVE-2026-107806 | Critical RCE A critical authenticated Remote Code Execution vulnerability affects nginx-ui versions 2.3.8–2.4.x. Upgrade to 2.5.0 or later to mitigate the issue. 🔎 Technical details & PoC: https://pocbit.org/pocs/cve-2026-107806 #CyberSecurity #CVE #RCE #InfoSec #nginx

    0002093
    633 followersView on X
  • zoomeyebot@zoomeyebot

    🚨 Nginx UI Authenticated RCE via Backup Restore (CVE-2026-107806) Critical Vulnerability Alert! 0xJacky Nginx UI (>= 2.3.8, < 2.5.0) is affected by CVE-2026-107806. 🔍 Identify Targets via ZoomEye: Search Dork: app="Nginx UI" Exposure: 10k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJOZ2lueCBVSSI%3D #Infosec #CyberSecurity #ZoomEye

    0000034
    25 followersView on X
  • Upwind Security MDR@UpwindMDR

    🚨Critical - Nginx UI Authenticated RCE via Restore Config Overwrite (CVE-2026-107806) Nginx UI’s backup restore flow lets an admin POST attacker-controlled key material + manifest to /api/restore to overwrite app.ini and protected nginx command settings (e.g., TestConfigCmd). Triggering /api/nginx/test then executes the injected command in the Nginx UI runtime context, leading to full RCE. 👉Affected: http://github.com/0xJacky/Nginx-UI

    0000068
    315 followersView on X

Explore more