Nginxui
Nginxui Nginx UI: vulnerabilidades y CVE
Nginxui Nginx UI tiene 23 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE23
Últimos 12 meses15
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-44015 | Crítica (9.9) | 0.39% | — | 12 may 2026 | Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and… |
| CVE-2026-42238 | Crítica (9) | 0.83% | — | 4 may 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticated during the first 10 minutes after… |
| CVE-2026-42223 | Media (6.5) | 0.41% | — | 4 may 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/settings.go:24-65) serializes all settings structs to JSON and returns them to authenticated… |
| CVE-2026-42222 | Crítica (9.8) | 0.47% | — | 4 may 2026 | Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of… |
| CVE-2026-42221 | Crítica (9.8) | 1.6% | — | 4 may 2026 | Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim the initial administrator account on a fresh nginx-ui instance during… |
| CVE-2026-42220 | Media (6.5) | 0.40% | — | 4 may 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /api/settings and retrieve sensitive configuration values, including node.secret. The same… |
| CVE-2026-34403 | Media (5.5) | 0.22% | — | 20 abr 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui use a gorilla/websocket Upgrader with CheckOrigin unconditionally returning true, allowing… |
| CVE-2026-33031 | Alta (8.6) | 0.39% | — | 20 abr 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an administrator can use previously issued API tokens for up to the token lifetime. In practice, disabling a… |
| CVE-2026-33026 | Crítica (9.4) | 0.21% | — | 30 mar 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration… |
| CVE-2026-33032 | Crítica (9.8) | 2.5% | — | 30 mar 2026 | Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both… |
| CVE-2026-33030 | Crítica (9.9) | 0.38% | — | 30 mar 2026 | Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to access, modify,… |
| CVE-2026-33029 | Media (6.9) | 0.48% | — | 30 mar 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in the logrotate configuration allows an authenticated user to cause a complete Denial of Service… |
| CVE-2026-33028 | Alta (7.1) | 0.59% | — | 30 mar 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerable to a Race Condition. Due to the complete absence of synchronization mechanisms (Mutex) and… |
| CVE-2026-33027 | Media (6.9) | 0.55% | — | 30 mar 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend… |
| CVE-2026-27944 | Crítica (9.8) | 1.0% | — | 5 mar 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the… |
| CVE-2024-49368 | Alta (8.9) | 28% | — | 21 oct 2024 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary… |
| CVE-2024-49367 | Media (5.5) | 0.64% | — | 21 oct 2024 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, the log path of nginxui is controllable. This issue can be combined with the directory traversal at `/api/configs` to read… |
| CVE-2024-49366 | Alta (7.7) | 0.60% | — | 21 oct 2024 | Nginx UI is a web user interface for the Nginx web server. Nginx UI v2.0.0-beta.35 and earlier gets the value from the json field without verification, and can construct a value value in the form of `../../`. Arbitrary… |
| CVE-2024-23828 | Alta (8.8) | 1.1% | — | 29 ene 2024 | Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when changing the value of test_config_cmd or start_cmd. This vulnerability… |
| CVE-2024-23827 | Crítica (9.8) | 0.70% | — | 29 ene 2024 | Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows… |
| CVE-2024-22198 | Alta (8.8) | 4.1% | — | 11 ene 2024 | Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. The `Home > Preference` page exposes a list of system settings such as… |
| CVE-2024-22196 | Media (6.5) | 0.58% | — | 11 ene 2024 | Nginx-UI is an online statistics for Server Indicators Monitor CPU usage, memory usage, load average, and disk usage in real-time. This issue may lead to information disclosure. By using `DefaultQuery`, the `"desc"`… |
| CVE-2024-22197 | Alta (8.8) | 1.5% | — | 11 ene 2024 | Nginx-ui is online statistics for Server Indicators Monitor CPU usage, memory usage, load average, and disk usage in real-time. The `Home > Preference` page exposes a small list of nginx settings such as `Nginx Access… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.