« Volver al listado

Nginxui

Nginxui Nginx UI: vulnerabilidades y CVE

Nginxui Nginx UI tiene 23 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE23
Últimos 12 meses15
Críticas9
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-44015Crítica (9.9)0.39%—12 may 2026
Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and…
CVE-2026-42238Crítica (9)0.83%—4 may 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticated during the first 10 minutes after…
CVE-2026-42223Media (6.5)0.41%—4 may 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/settings.go:24-65) serializes all settings structs to JSON and returns them to authenticated…
CVE-2026-42222Crítica (9.8)0.47%—4 may 2026
Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of…
CVE-2026-42221Crítica (9.8)1.6%—4 may 2026
Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim the initial administrator account on a fresh nginx-ui instance during…
CVE-2026-42220Media (6.5)0.40%—4 may 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /api/settings and retrieve sensitive configuration values, including node.secret. The same…
CVE-2026-34403Media (5.5)0.22%—20 abr 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui use a gorilla/websocket Upgrader with CheckOrigin unconditionally returning true, allowing…
CVE-2026-33031Alta (8.6)0.39%—20 abr 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an administrator can use previously issued API tokens for up to the token lifetime. In practice, disabling a…
CVE-2026-33026Crítica (9.4)0.21%—30 mar 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration…
CVE-2026-33032Crítica (9.8)2.5%—30 mar 2026
Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both…
CVE-2026-33030Crítica (9.9)0.38%—30 mar 2026
Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to access, modify,…
CVE-2026-33029Media (6.9)0.48%—30 mar 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in the logrotate configuration allows an authenticated user to cause a complete Denial of Service…
CVE-2026-33028Alta (7.1)0.59%—30 mar 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerable to a Race Condition. Due to the complete absence of synchronization mechanisms (Mutex) and…
CVE-2026-33027Media (6.9)0.55%—30 mar 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend…
CVE-2026-27944Crítica (9.8)1.0%—5 mar 2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the…
CVE-2024-49368Alta (8.9)28%—21 oct 2024
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary…
CVE-2024-49367Media (5.5)0.64%—21 oct 2024
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, the log path of nginxui is controllable. This issue can be combined with the directory traversal at `/api/configs` to read…
CVE-2024-49366Alta (7.7)0.60%—21 oct 2024
Nginx UI is a web user interface for the Nginx web server. Nginx UI v2.0.0-beta.35 and earlier gets the value from the json field without verification, and can construct a value value in the form of `../../`. Arbitrary…
CVE-2024-23828Alta (8.8)1.1%—29 ene 2024
Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when changing the value of test_config_cmd or start_cmd. This vulnerability…
CVE-2024-23827Crítica (9.8)0.70%—29 ene 2024
Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows…
CVE-2024-22198Alta (8.8)4.1%—11 ene 2024
Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. The `Home > Preference` page exposes a list of system settings such as…
CVE-2024-22196Media (6.5)0.58%—11 ene 2024
Nginx-UI is an online statistics for Server Indicators​​ Monitor CPU usage, memory usage, load average, and disk usage in real-time. This issue may lead to information disclosure. By using `DefaultQuery`, the `"desc"`…
CVE-2024-22197Alta (8.8)1.5%—11 ene 2024
Nginx-ui is online statistics for Server Indicators​​ Monitor CPU usage, memory usage, load average, and disk usage in real-time. The `Home > Preference` page exposes a small list of nginx settings such as `Nginx Access…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application6
  2. T1210 Exploitation of Remote Services5
  3. T1078 Valid Accounts4
  4. T1059 Command and Scripting Interpreter2
  5. T1078.001 Default Accounts2
  6. T1565.001 Stored Data Manipulation2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.