CVE-2026-50892
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obtain the TLS private key material via a crafted GET request.
Published 2026-06-15. Last modified 2026-06-17.