Skip to content
RCE Vulnerability in Nginx UI Disclosed

RCE Vulnerability in Nginx UI Disclosed

First seen 10 Oct 2026, 07:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 10, 2026 at 08:35 UTC
  • •CVE-2026-107806 allows RCE via forged backup uploads.
  • •Affected versions include nginx-ui 2.3.11 to 2.4.x.
  • •Patch released in version 2.5.0 on October 9, 2026.

A remote code execution vulnerability (CVE-2026-107806) has been identified in Nginx UI, affecting versions 2.3.11 through 2.4.x. Authenticated users can exploit this flaw by uploading a forged backup via the POST /api/restore endpoint, which allows them to overwrite sensitive application settings. This vulnerability was validated on nginx-ui 2.3.11 in a local Docker environment. The flaw enables attackers to execute arbitrary commands within the Nginx UI runtime context, impacting confidentiality, integrity, and availability. A fix was released in version 2.5.0 on October 9, 2026. The vulnerability has a CVSS score of 9.4, categorizing it as. Administrators are urged to update to the latest version to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-09
CVE-2026-107806 published
A critical RCE vulnerability in Nginx UI was disclosed with a CVSS score of 9.4.
Advisories.Gitlab
2026-10-09
Patch released for nginx-ui
Version 2.5.0 was released to address the critical vulnerability CVE-2026-107806.
github.com

More articles in this cluster (4)

Following this threat?

Track CVE-2026-107806 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions are affected?
Nginx UI versions 2.3.11 through 2.4.x are affected by CVE-2026-107806.
What is the impact of this vulnerability?
The vulnerability allows authenticated users to execute arbitrary commands, compromising the application's confidentiality, integrity, and availability.
How can I mitigate this risk?
Update to nginx-ui version 2.5.0 or later to address the vulnerability.