CVE-2026-90581: CYM1102 Nginxwebui

Medium severity, CVSS 6.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.

Affected products

  • CYM1102 Nginxwebui: version 4.4.0 only; version 4.4.1 only; version 4.4.2 only

Published 2026-09-13. Last modified 2026-09-14.