Skip to content
Threat Feed
critical threat exploited

Authenticated Remote Code Execution in Nginx-UI via Backup Restoration

An authenticated user can achieve remote code execution in Nginx-UI by uploading a maliciously crafted backup file that overwrites application configuration settings.

CVE search metadata

CVE search record: CVE-2026-107806. KEV: no. Product: Nginx-UI (1.9.10-0.20260421071512-7864e378f5cf to < 1.9.10-0.20260728074146-a467ed652591), Nginx-UI (>= 1.9.10-0.20250517140552-daee3ac7ade1, < 1.9.10-0.20260728074558-95cd21b70814), Nginx-UI (>= 1.9.10-0.20250517140552-daee3ac7ade1, < 1.9.10-0.20260728074433-a3999bd78a3b). Brief: Authenticated Remote Code Execution in Nginx-UI via Backup Restoration. Brief link: https://feed.craftedsignal.io/briefs/2026-10-nginx-ui-rce/

What's new

  • 1. added detection rule: Detects CVE-2026-107809 Exploitation - CSRF Attempt Against Nginx-UI API Oct 9, 21:28 via ghsa
  • 2. added coverage for Nginx-UI (>= 1.9.10-0.20250517140552-daee3ac7ade1, < 1.9.10-0.20260728074558-95cd21b70814) Oct 9, 21:27 via ghsa

Nginx-UI is susceptible to a critical authenticated remote code execution (RCE) vulnerability, tracked as CVE-2026-107806. The issue resides in the backup restoration feature, specifically within the POST /api/restore endpoint. An authenticated user can bypass configuration security constraints by providing a forged backup file. The application fails to strictly validate the contents of the restored backup, allowing an attacker to modify app.ini. By injecting arbitrary commands into the TestConfigCmd field within this configuration file, an attacker can trigger command execution via the POST /api/nginx/test endpoint. This vulnerability allows an attacker to achieve full control over the runtime environment of the Nginx-UI service, potentially leading to unauthorized data access and persistence within the underlying system. This was identified in Nginx-UI versions between 1.9.10-0.20260421071512-7864e378f5cf and 1.9.10-0.20260728074146-a467ed652591.

Attack Chain

  1. Attacker authenticates to the target Nginx-UI instance and obtains a valid JWT.
  2. Attacker initiates an authorized backup request to GET /api/backup to retrieve current encrypted backup artifacts and the required X-Backup-Security token.
  3. Attacker decrypts the retrieved backup archive using the extracted security token and IV.
  4. Attacker modifies the app.ini file within the decrypted archive to include a malicious payload in the TestConfigCmd setting.
  5. Attacker re-encrypts the modified backup archive and regenerates the manifest signature using the same HMAC key derivation logic.
  6. Attacker uploads the forged backup via POST /api/restore with the malicious payload included.
  7. Attacker invokes POST /api/nginx/test to force the application to execute the modified TestConfigCmd.
  8. Arbitrary code executes within the Nginx-UI container context, completing the exploit chain.

Impact

Successful exploitation results in full command execution within the Nginx-UI runtime environment. An attacker can use this access to read or modify sensitive configuration data, extract JWT secrets, corrupt application state, or move laterally within the host environment, depending on the container's privileges and host integration.

Recommendation

Prioritized actions for detection and mitigation:

  • Patch Nginx-UI to version 1.9.10-0.20260728074146-a467ed652591 or later to remediate CVE-2026-107806.
  • Deploy WAF or web server rules to audit or block POST requests to /api/restore and /api/nginx/test originating from non-administrative user accounts.
  • Monitor logs for unusual configuration changes, specifically modifications to app.ini or attempts to trigger nginx test command execution from suspicious user sessions.
  • Restrict access to the Nginx-UI interface to trusted internal networks only to minimize the exposure of administrative endpoints.

Immediate actions

Patch Nginx-UI to 1.9.10-0.20260728074146-a467ed652591 or later.

IT Operations 24h

Mitigations

Restrict access to /api/restore and /api/nginx/test endpoints.

immediate IT Operations

CVE-2026-107806

Detection coverage 2

Detect Nginx-UI Backup Restoration Attempt

high

Detects exploitation of CVE-2026-107806 via POST requests to the /api/restore endpoint.

sigma tactics: execution techniques: T1059.003 sources: webserver

Detects CVE-2026-107809 Exploitation - CSRF Attempt Against Nginx-UI API

high

Detects potential CSRF attempts where a POST/PUT/DELETE request to sensitive Nginx-UI endpoints occurs without a valid Origin or Referer header matching the expected application host.

sigma tactics: initial_access sources: webserver

Detection queries are available on the platform. Get full rules →