Product
medium
advisory
CVE-2026-66362: Injection Vulnerability in NGINX Gateway Fabric
1 TTP 1 CVEAn injection vulnerability in the NGINX Gateway Fabric configuration generator allows authenticated users to inject arbitrary NGINX directives into the configuration when using NGINX Plus as the data plane.
NGINX Gateway Fabric
vulnerability
kubernetes
ingress
injection
1t
1c
high
advisory
CVE-2026-50107: NGINX Gateway Fabric Configuration Injection Vulnerability
2 rules 1 TTP 5 CVEs 2 IOCsAn injection vulnerability, CVE-2026-50107, exists in the NGINX configuration generator component of NGINX Gateway Fabric when configured with NGINX Plus or NGINX Open Source as the data plane, allowing authenticated attackers with CRD modification permissions to inject arbitrary NGINX configuration directives via unsanitized user-supplied string values in the access log format setting, leading to control plane compromise and potential defense evasion or system impact.
PoC
NGINX Plus +10
config-injection
nginx
kubernetes
cloud-native
web-vulnerability
cve
2r
1t
5c
2i
updated