CVE-2026-42222: Nginxui Nginx UI

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are available.

Affected products

  • Nginxui Nginx UI: version 2.3.5 only

Published 2026-05-04. Last modified 2026-06-17.