{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/nginx-ui--1.9.10-0.20250517140552-daee3ac7ade1--1.9.10-0.20260728074433-a3999bd78a3b/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:0xjacky:nginx_ui:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-107805"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Nginx UI (2.5.0-2.5.x)","Nginx-UI (\u003e= 1.9.10-0.20250517140552-daee3ac7ade1, \u003c 1.9.10-0.20260728091109-0ecbd106c37b, 2.4.2)","Nginx UI (\u003e= 1.9.10-0.20250517140552-daee3ac7ade1, \u003c 1.9.10-0.20260728074433-a3999bd78a3b)","Nginx UI (\u003e= 1.9.10-0.20250517140552-daee3ac7ade1, \u003c 1.9.10-0.20260728074146-a467ed652591)"],"_cs_severities":["high"],"_cs_tags":["denial-of-service","webserver","availability","credential-exposure","authentication-bypass","cve"],"_cs_type":"advisory","_cs_vendors":["0xJacky"],"content_html":"\u003cp\u003eNginx UI versions 2.5.0 through 2.5.x are vulnerable to a high-severity denial-of-service condition involving improper request processing. The application's node-signature authentication logic incorrectly stages the body of incoming requests to temporary files on disk before validating the associated cryptographic signature or body digest.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated remote attacker capable of reaching the Nginx UI API can initiate requests containing syntactically correct signature metadata but arbitrary, large body payloads. Because the application processes these requests and commits them to temporary storage prior to authentication, a stream of concurrent, malicious requests can consume system-level disk capacity, saturate I/O throughput, and exhaust request-processing threads. This behavior disrupts the availability of Nginx UI and may impact other services residing on the same infrastructure. The vulnerability is strictly an availability concern and does not facilitate unauthorized access, data confidentiality loss, or integrity compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for resource exhaustion, leading to a denial of service. The impact is primarily on system availability, where excessive concurrent requests can lead to full temporary partitions or I/O starvation. The degree of impact depends heavily on environmental factors such as available disk quotas, configured reverse-proxy body limits, and server-side concurrency constraints.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize upgrading to Nginx UI 2.6.0 or later to mitigate the vulnerability. The patch introduces a check to authenticate request metadata prior to staging and implements improved request body streaming with size constraints and automatic cleanup for discarded requests.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Nginx UI to 2.6.0 or later immediately.\u003c/li\u003e\n\u003cli\u003eReview temporary filesystem usage patterns to detect spikes in \u003ccode\u003e/tmp\u003c/code\u003e or designated staging directories associated with Nginx UI.\u003c/li\u003e\n\u003cli\u003eImplement application-level request size limits in front-end reverse proxies (e.g., standard Nginx or HAProxy) to prevent oversized payloads from reaching the application API.\u003c/li\u003e\n\u003cli\u003eConfigure system-level disk quotas for the service account running Nginx UI to contain the impact of storage exhaustion.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T21:28:42Z","date_published":"2026-10-09T21:23:53Z","id":"https://feed.craftedsignal.io/briefs/2026-10-nginx-ui-dos/","summary":"An unauthenticated remote attacker can exploit CVE-2026-107805 in Nginx UI by sending malicious requests that trigger premature staging of large, unsigned request bodies, leading to disk space and I/O exhaustion.","title":"Unauthenticated Denial of Service via Temporary File Exhaustion in Nginx UI","url":"https://feed.craftedsignal.io/briefs/2026-10-nginx-ui-dos/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-107806"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Nginx-UI (1.9.10-0.20260421071512-7864e378f5cf to \u003c 1.9.10-0.20260728074146-a467ed652591)","Nginx-UI (\u003e= 1.9.10-0.20250517140552-daee3ac7ade1, \u003c 1.9.10-0.20260728074558-95cd21b70814)","Nginx-UI (\u003e= 1.9.10-0.20250517140552-daee3ac7ade1, \u003c 1.9.10-0.20260728074433-a3999bd78a3b)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","cve-2026-107806","nginx-ui","vulnerability","authentication-bypass","cve-2026-107808","web-application","n8n","csrf","cve-2026-107809"],"_cs_type":"threat","_cs_vendors":["Nginx-UI"],"content_html":"\u003cp\u003eNginx-UI is susceptible to a critical authenticated remote code execution (RCE) vulnerability, tracked as CVE-2026-107806. The issue resides in the backup restoration feature, specifically within the \u003ccode\u003ePOST /api/restore\u003c/code\u003e endpoint. An authenticated user can bypass configuration security constraints by providing a forged backup file. The application fails to strictly validate the contents of the restored backup, allowing an attacker to modify \u003ccode\u003eapp.ini\u003c/code\u003e. By injecting arbitrary commands into the \u003ccode\u003eTestConfigCmd\u003c/code\u003e field within this configuration file, an attacker can trigger command execution via the \u003ccode\u003ePOST /api/nginx/test\u003c/code\u003e endpoint. This vulnerability allows an attacker to achieve full control over the runtime environment of the Nginx-UI service, potentially leading to unauthorized data access and persistence within the underlying system. This was identified in Nginx-UI versions between 1.9.10-0.20260421071512-7864e378f5cf and 1.9.10-0.20260728074146-a467ed652591.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the target Nginx-UI instance and obtains a valid JWT.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an authorized backup request to \u003ccode\u003eGET /api/backup\u003c/code\u003e to retrieve current encrypted backup artifacts and the required \u003ccode\u003eX-Backup-Security\u003c/code\u003e token.\u003c/li\u003e\n\u003cli\u003eAttacker decrypts the retrieved backup archive using the extracted security token and IV.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the \u003ccode\u003eapp.ini\u003c/code\u003e file within the decrypted archive to include a malicious payload in the \u003ccode\u003eTestConfigCmd\u003c/code\u003e setting.\u003c/li\u003e\n\u003cli\u003eAttacker re-encrypts the modified backup archive and regenerates the manifest signature using the same HMAC key derivation logic.\u003c/li\u003e\n\u003cli\u003eAttacker uploads the forged backup via \u003ccode\u003ePOST /api/restore\u003c/code\u003e with the malicious payload included.\u003c/li\u003e\n\u003cli\u003eAttacker invokes \u003ccode\u003ePOST /api/nginx/test\u003c/code\u003e to force the application to execute the modified \u003ccode\u003eTestConfigCmd\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eArbitrary code executes within the Nginx-UI container context, completing the exploit chain.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full command execution within the Nginx-UI runtime environment. An attacker can use this access to read or modify sensitive configuration data, extract JWT secrets, corrupt application state, or move laterally within the host environment, depending on the container's privileges and host integration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and mitigation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch Nginx-UI to version 1.9.10-0.20260728074146-a467ed652591 or later to remediate CVE-2026-107806.\u003c/li\u003e\n\u003cli\u003eDeploy WAF or web server rules to audit or block \u003ccode\u003ePOST\u003c/code\u003e requests to \u003ccode\u003e/api/restore\u003c/code\u003e and \u003ccode\u003e/api/nginx/test\u003c/code\u003e originating from non-administrative user accounts.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual configuration changes, specifically modifications to \u003ccode\u003eapp.ini\u003c/code\u003e or attempts to trigger nginx test command execution from suspicious user sessions.\u003c/li\u003e\n\u003cli\u003eRestrict access to the Nginx-UI interface to trusted internal networks only to minimize the exposure of administrative endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T21:28:05Z","date_published":"2026-10-09T21:23:28Z","id":"https://feed.craftedsignal.io/briefs/2026-10-nginx-ui-rce/","summary":"An authenticated user can achieve remote code execution in Nginx-UI by uploading a maliciously crafted backup file that overwrites application configuration settings.","title":"Authenticated Remote Code Execution in Nginx-UI via Backup Restoration","url":"https://feed.craftedsignal.io/briefs/2026-10-nginx-ui-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Nginx UI (\u003e= 1.9.10-0.20250517140552-Daee3ac7ade1, \u003c 1.9.10-0.20260728074433-A3999bd78a3b)","version":"https://jsonfeed.org/version/1.1"}