CVE-2026-42221Disclosure(nginxui / nginx_ui)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim the initial administrator account on a fresh nginx-ui instance during the first-run setup window. The public /api/install endpoint is reachable without authentication, and the request-encryption flow only protects payload confidentiality in transit; it does not authenticate who is allowed to perform installation. A remote attacker who reaches the service before the legitimate operator can set the admin email, username, and password, causing permanent initial-instance takeover. This issue has been patched in version 2.3.8.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nginx_ui

Threat summary

  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-05-04); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
nginx_ui

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-04: 2Mentions · 2026-05-05: 1Mentions · 2026-05-11: 1Mentions · 2026-09-07: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-05: 1Technical Details · 2026-09-07: 105-0405-0505-1109-07
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-042
Disclosure2
2026-05-051
Disclosure1
2026-05-111
General1
2026-09-071
Disclosure1
Full discourse5 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-42221 - high 🚨 Nginx UI <= 2.3.7 - Unauthenticated Installer Exposure > Nginx UI 2.0.0 to 2.3.8 contains an authentication bypass caused by unauthenticated a... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-42221 @pdnuclei #NucleiTemplates #cve

    Post summary

    This tweet announces CVE-2026-42221 for Nginx UI versions up to 2.3.7, outlining an unauthenticated installer exposure leading to authentication bypass, with no evidence of active exploitation, PoC, or patch information.

    010811966
    1.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42221 Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim the initial admin… https://www.cve.org/CVERecord?id=CVE-2026-42221

    Post summary

    The post cites CVE‑2026‑42221, noting an unauthenticated privilege‑escalation flaw in older Nginx UI releases, but provides no details on exploits, PoC, patches, or active usage.

    00010150
    57.4K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-42221: Nginx UI Authentication Bypass - What It Means for Your Business and How to Respond https://hubs.li/Q04g5l1g0

    Post summary

    The snippet signals a general advisory about an Nginx UI authentication bypass, but offers no concrete details, PoC, exploit, or mitigation information.

    0000021
    30 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42221 Unauthenticated Administrator Account Takeover in Nginx UI Versions 2.0.0-2.3.7 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42221

    Post summary

    The text announces CVE-2026-42221 as an unauthenticated administrator account takeover vulnerability affecting Nginx UI versions 2.0.0-2.3.7, providing basic technical details but no PoC, exploit, or patch information.

    0000046
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42221 Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim the initial admin… https://www.cve.org/CVERecord?id=CVE-2026-42221 ----- Traducción: CVE-2026-42221 Ngi… http://infoflow.cloud`

    Post summary

    The snippet announces CVE-2026-42221, noting it allows unauthenticated network attackers to gain administrative access in Nginx UI versions 2.0.0 through 2.3.7, but does not provide a PoC, exploit, or remediation.

    0000027
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnginxuinginx_ui---

Explore more