Skip to content
CVSS 8.1 · HIGH

CVE-2026-42222

Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are available.

View on NVD

Analysis

Nginx UI is a popular open-source management interface for Nginx servers. This vulnerability allows an unauthenticated attacker to take over the application during the installation phase, leading to full control over Nginx configurations. High severity and realistic exploit scenario for anyone deploying new instances.

Severity

Score: 8.1(HIGH)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: HIGH
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-284CWE-306

EPSS

Probability of exploitation (next 30 days): 0.0004 (0.0%)
Percentile: 12.4%
EPSS: 2026-05-06

Affects

nginxui:nginx_ui

Technical description

Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are available.

Published: 5/4/2026, 9:16:32 PM
Last modified: 5/6/2026, 5:47:59 PM

References

HomeEventsBlogResourcesTeam