Nginx UI: seven CVEs published 9 Oct (CVSS up to 8.8) — node secret accepted in URLs, passkey-only 2FA skipped at login, cookie-JWT CSRF, symlink backup restore, node-token impersonation and an unsigned self-upgrade; all fixed in 2.5.0
The Nginx UI project (0xJacky/nginx-ui, a web console for managing Nginx servers) published seven GitHub advisories and CVEs on 9 October 2026 for versions 2.0.0 up to 2.5.0; the fixes shipped in 2.5.0 (released 29 July). CVE-2026-107807 (CVSS 3.1 8.8): the Node.Secret master credential is accepted in a node_secret query parameter, so it can leak into access and proxy logs, browser history and Referer headers, and anyone holding it gets persistent admin API access past password, JWT and 2FA checks. CVE-2026-107808 (8.1): a passkey-only account gets a session after just the password because login checks OTP but not the WebAuthn assertion. CVE-2026-107809 (8.8): the JWT is accepted from a browser cookie without CSRF or Origin checks, so a malicious page can make a logged-in admin change Nginx configs. CVE-2026-107811 (8.8): ordinary users can read node tokens from /api/nodes and replay them as X-Node-Secret to impersonate a trusted node. CVE-2026-107813 (8.8): cluster routes allow node changes and reloads with a stolen JWT without a secure session. CVE-2026-107810 (8.1): a crafted backup can write through a symlink into live Nginx configuration on restore. CVE-2026-107812 (7.5): self-upgrade trusts a digest from the same mirror as the binary. No exploitation reported. Primary: Nginx UI GitHub security advisories.
- Product
- Nginx UI (0xJacky/nginx-ui) web management console for Nginx
- Versions
- 2.0.0 to before 2.5.0
- CVSS
- (CVSS 3.1: CVE-2026-107807, CVE-2026-107809, CVE-2026-107811, CVE-2026-107813)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (CVE-2026-107807) - Exploited in Australia?
- unknown
- Patch to
- Upgrade Nginx UI to 2.5.0 or later. Rotate the Node.Secret and node tokens, search access and proxy logs for node_secret= in URLs, keep the console off the internet (VPN or allow-list only) and require TOTP or a passkey on admin accounts.
Primary: Nginx UI GHSA-pvgv-gcp7-v38g — Node.Secret accepted via query parameter (CVE-2026-107807, 9 Oct 2026) · Vendor: Nginx UI v2.5.0 release · CVE: CVE-2026-107807, CVE-2026-107808, CVE-2026-107809, CVE-2026-107811, CVE-2026-107813, CVE-2026-107810, CVE-2026-107812 · Nginx UI — all GitHub security advisories
