
CVE-2026-42220 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /api/settings and retrieve sensitive configurati… https://www.cve.org/CVERecord?id=CVE-2026-42220
Post summary
The CVE report reveals that Nginx UI versions older than 2.3.8 allow authenticated users to retrieve sensitive configuration via a GET request to /api/settings.


