CVE-2026-42222
Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are available.
View on NVDAnalysis
Nginx UI is a popular open-source management interface for Nginx servers. This vulnerability allows an unauthenticated attacker to take over the application during the installation phase, leading to full control over Nginx configurations. High severity and realistic exploit scenario for anyone deploying new instances.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HCWE-284CWE-306EPSS
Affects
nginxui:nginx_uiTechnical description
Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are available.