CVE-2026-42223Disclosure(nginxui / nginx_ui)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/settings.go:24-65) serializes all settings structs to JSON and returns them to authenticated users. Many sensitive fields are tagged with protected:"true" - however, this tag is only enforced during writes (via ProtectedFill in SaveSettings) and is completely ignored during reads. This exposes 40+ protected fields including JwtSecret (enabling auth token forgery), NodeSecret (enabling cluster node impersonation), OIDC ClientSecret (enabling OAuth account takeover), and the IP whitelist configuration. This issue has been patched in version 2.3.8.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nginx_ui

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-04); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
nginx_ui

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-04: 2Mentions · 2026-05-05: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-05: 105-0405-05
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-042
Disclosure1General1
2026-05-051
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-42223 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/settings.go:24-65) serializes all setting… https://www.cve.org/CVERecord?id=CVE-2026-42223

    Post summary

    The post discloses details of CVE-2026-42223, explaining that the GetSettings API handler in Nginx UI versions prior to 2.3.8 serializes all settings, highlighting a potential vulnerability but providing no evidence of exploitation or remedy.

    00010148
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42223 Information Disclosure in Nginx UI Prior to Version 2.3.8 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42223 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post introduces CVE-2026-42223 as an information disclosure flaw in Nginx UI versions before 2.3.8, linking to external details but providing no exploit, patch, or threat information.

    0000047
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-42223 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/settings.go:24-65) serializes all setting… https://www.cve.org/CVERecord?id=CVE-2026-42223 ----- Traducción: CVE-2026-42223 Ngi… http://infoflow.cloud`

    Post summary

    The tweet only notes the existence of CVE-2026-42223 in Nginx UI and provides a link to the official CVE record, with no further technical or exploitation details.

    0000027
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnginxuinginx_ui---

Explore more