CVE-2026-107811: 0xjacky Nginx-UI

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenticated users can access /api/nodes and /api/nodes/:id, whose responses serialize the node token field. The same token is accepted as X-Node-Secret by AuthRequired and maps the request to initUser, allowing the user to impersonate a trusted node against a reachable cluster member. This cross-node authentication bypass can expose sensitive management operations, including configuration synchronization and service restart. This issue is fixed in version 2.5.0.

Affected products

  • 0xjacky Nginx-UI: from 2.0.0, before 2.5.0 (fixed in 2.5.0)

Published 2026-10-09. Last modified 2026-10-09.