CVE-2026-42238Disclosure(nginxui / nginx_ui)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch nginxui nginx_ui systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticated during the first 10 minutes after process startup on any fresh installation. An unauthenticated remote attacker can upload a crafted backup archive that overwrites the application's configuration file (app.ini) and SQLite database. Because the attacker controls the restored app.ini, they can inject an arbitrary OS command into the TestConfigCmd setting. After the application automatically restarts to apply the restored config, a single follow-up request triggers that command as the user running nginx-ui — typically root in Docker deployments. This issue has been patched in version 2.3.8.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nginx_ui

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 13 mentions across 7 observed days
  • Momentum state: rising

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 10 signals
  • Disclosure: 7 classified signals
  • General: 3 classified signals
  • Peaked 1d ago at 5 mentions (2026-05-13); latest day: 1
  • 13 total mentions across 7 days

Affected systems

Vendors
Products
nginx_ui

Deep dive

Activity timeline13 mentions / 7d
01345Mentions · 2026-04-28: 1Mentions · 2026-05-04: 2Mentions · 2026-05-05: 2Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Mentions · 2026-05-13: 5Mentions · 2026-06-11: 1Active Exploitation · 2026-05-06: 1Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-05: 1Technical Details · 2026-04-28: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-05: 2Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-13: 2Technical Details · 2026-06-11: 104-2805-0405-0505-0605-0705-1306-11
Signal classification4 categories
Disclosure
753.8%
General
323.1%
Patch
215.4%
Active Exploitation
17.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-281
Patch1
2026-05-042
Disclosure2
2026-05-052
Disclosure1Patch1
2026-05-061
Active Exploitation1
2026-05-071
Disclosure1
2026-05-135
Disclosure3General2
2026-06-111
General1
Full discourse13 posts
  • Gray Hats@the_yellow_fall
    Patch

    Critical 9.0 CVSS RCE in Nginx UI (CVE-2026-42238) exploits a 10-minute unauthenticated window. Attackers can seize root control. Patch to the latest version now. #NginxUI #CyberSecurity #RCE #InfoSec #CVE202642238 #WebSecurity #PatchNow #Nginx https://securityonline.info/nginx-ui-rce-vulnerability-cve-2026-42238-auth-bypass/ https://t.co/phB2w9J7yX

    Post summary

    The tweet announces a critical RCE vulnerability (CVE-2026-42238) in Nginx UI, highlights its high severity, and urges users to apply the latest patch immediately.

    0801151.0K
    12.5K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Nginx UI RCE (CVE-2026-42238) Critical flaw allows unauthenticated attackers to gain full server control via a 10-minute exposure window during startup/restart. By abusing the restore endpoint, attackers can overwrite configs and execute arbitrary commands as root. Patch immediately and avoid unnecessary restarts - this is full takeover risk.

    Post summary

    CVE-2026-42238 is a critical Nginx UI RCE that permits unauthenticated attackers to gain full server control via a 10‑minute window; immediate patching is strongly advised.

    0101191
    121 followersView on X
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    General

    CVE-2026-42238 is a good patch-discipline check. Affected systems / remote code execution. Public details are enough to start scoping. What would you check first if this hit your stack?

    Post summary

    The post highlights CVE‑2026‑42238 as a remote code execution risk that warrants patch checks, but offers no PoC, exploit code, or evidence of active exploitation.

    1000044
    331 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-42238 (CVSS 9.8) — nginxui nginx ui. CVE: CVE-2026-42238 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    An advisory announcing CVE-2026-42238 for nginxui with a CVSS 9.8 score and critical severity.

    1000020
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-42238 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    A validated threat intelligence pipeline releases a critical advisory for CVE-2026-42238 with a CVSS score of 9.8, but no PoC, exploit, patch, or exploitation evidence is provided.

    1000040
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE: CVE-2026-42238 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Nginx UI is a web user interface for the Nginx web server.

    Post summary

    The entry reports CVE-2026-42238 with a critical CVSS score for Nginx UI but provides no further technical detail or remediation guidance.

    1000027
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-42238 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The entry merely lists CVE-2026-42238 with its CVSS score and critical severity, offering no further details or actionable information.

    1000030
    210 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2026-42238 Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore https://github.com/advisories/GHSA-4pvg-prr3-9cxr

    Post summary

    The advisory announces CVE‑2026‑42238, noting an unauthenticated RCE in Nginx‑UI via backup restore, with a reference to the corresponding GitHub advisory.

    00010321
    6.8K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42238 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely u… https://www.cve.org/CVERecord?id=CVE-2026-42238

    Post summary

    The post discloses that nginx-ui versions prior to 2.3.8 expose a backup restore endpoint, indicating a vulnerability that is mitigated by the 2.3.8 release.

    00010172
    57.4K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    https://lyrie.ai/research/research/cve-2026-42238-nginxui-nginx-ui #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet shares a link to a research page about CVE‑2026‑42238 but offers no additional details, PoC, exploit code, or evidence of active exploitation.

    0000023
    210 followersView on X
  • Technology Interpreters, Inc.@TechTranslators
    Active Exploitation

    Today (Wed, May 6): 1 KEV add, 10 critical CVEs. PAN-OS Captive Portal RCE went out earlier. Long tail: - Apache Wicket session fixation (CVE-2026-40010) - Nginx-UI unauth RCE (CVE-2026-42238, CVSS 9.8) - phpMyFAQ unauth SQL injection (GHSA-289f-fq7w-6q2w)

    Post summary

    The message reports a KEV addition, highlights 10 critical CVEs with known exploitation and technical details, underscoring that active attacks are underway.

    0000066
    34 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42238 Unauthenticated Remote Code Execution in Nginx UI Before Version 2.3.8 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42238

    Post summary

    The text announces the discovery of an unauthenticated remote code execution flaw in Nginx UI versions prior to 2.3.8, providing no PoC, exploit, or mitigation details.

    0000048
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42238 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely u… https://www.cve.org/CVERecord?id=CVE-2026-42238 ----- Traducción: CVE-2026-42238 Ngi… http://infoflow.cloud`

    Post summary

    The post announces a newly disclosed vulnerability in nginx‑ui (prior to v2.3.8) involving an exposed backup restore endpoint, but it does not provide PoC, exploit, or patch details.

    0000029
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnginxuinginx_ui---

Explore more