« Volver al listado

Nginxui

Nginxui Nginx UI: vulnerabilidades y CVE

Nginxui Nginx UI tiene 23 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE23
Últimos 12 meses15
Críticas9
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-44015Crítica (9.9)0.39%—12 may 2026
Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and…
CVE-2026-42238Crítica (9)0.83%—4 may 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticated during the first 10 minutes after…
CVE-2026-42223Media (6.5)0.41%—4 may 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/settings.go:24-65) serializes all settings structs to JSON and returns them to authenticated…
CVE-2026-42222Crítica (9.8)0.47%—4 may 2026
Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of…
CVE-2026-42221Crítica (9.8)1.6%—4 may 2026
Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim the initial administrator account on a fresh nginx-ui instance during…
CVE-2026-42220Media (6.5)0.40%—4 may 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /api/settings and retrieve sensitive configuration values, including node.secret. The same…
CVE-2026-34403Media (5.5)0.22%—20 abr 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui use a gorilla/websocket Upgrader with CheckOrigin unconditionally returning true, allowing…
CVE-2026-33031Alta (8.6)0.39%—20 abr 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an administrator can use previously issued API tokens for up to the token lifetime. In practice, disabling a…
CVE-2026-33026Crítica (9.4)0.21%—30 mar 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration…
CVE-2026-33032Crítica (9.8)2.5%—30 mar 2026
Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both…
CVE-2026-33030Crítica (9.9)0.38%—30 mar 2026
Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to access, modify,…
CVE-2026-33029Media (6.9)0.48%—30 mar 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in the logrotate configuration allows an authenticated user to cause a complete Denial of Service…
CVE-2026-33028Alta (7.1)0.59%—30 mar 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerable to a Race Condition. Due to the complete absence of synchronization mechanisms (Mutex) and…
CVE-2026-33027Media (6.9)0.55%—30 mar 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend…
CVE-2026-27944Crítica (9.8)1.0%—5 mar 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the…
CVE-2024-49368Alta (8.9)28%—21 oct 2024
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary…
CVE-2024-49367Media (5.5)0.64%—21 oct 2024
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, the log path of nginxui is controllable. This issue can be combined with the directory traversal at `/api/configs` to read…
CVE-2024-49366Alta (7.7)0.60%—21 oct 2024
Nginx UI is a web user interface for the Nginx web server. Nginx UI v2.0.0-beta.35 and earlier gets the value from the json field without verification, and can construct a value value in the form of `../../`. Arbitrary…
CVE-2024-23828Alta (8.8)1.1%—29 ene 2024
Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when changing the value of test_config_cmd or start_cmd. This vulnerability…
CVE-2024-23827Crítica (9.8)0.70%—29 ene 2024
Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows…
CVE-2024-22198Alta (8.8)4.1%—11 ene 2024
Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. The `Home > Preference` page exposes a list of system settings such as…
CVE-2024-22196Media (6.5)0.58%—11 ene 2024
Nginx-UI is an online statistics for Server Indicators​​ Monitor CPU usage, memory usage, load average, and disk usage in real-time. This issue may lead to information disclosure. By using `DefaultQuery`, the `"desc"`…
CVE-2024-22197Alta (8.8)1.5%—11 ene 2024
Nginx-ui is online statistics for Server Indicators​​ Monitor CPU usage, memory usage, load average, and disk usage in real-time. The `Home > Preference` page exposes a small list of nginx settings such as `Nginx Access…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services5
  2. T1078 Valid Accounts3
  3. T1190 Exploit Public-Facing Application3
  4. T1078.001 Default Accounts2
  5. T1059 Command and Scripting Interpreter1
  6. T1090.001 Internal Proxy1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.