<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-107806 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-107806/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 21:23:28 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-107806/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authenticated Remote Code Execution in Nginx-UI via Backup Restoration</title><link>https://feed.craftedsignal.io/briefs/2026-10-nginx-ui-rce/</link><pubDate>Fri, 09 Oct 2026 21:23:28 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-nginx-ui-rce/</guid><description>An authenticated user can achieve remote code execution in Nginx-UI by uploading a maliciously crafted backup file that overwrites application configuration settings.</description><content:encoded><![CDATA[<p>Nginx-UI is susceptible to a critical authenticated remote code execution (RCE) vulnerability, tracked as CVE-2026-107806. The issue resides in the backup restoration feature, specifically within the <code>POST /api/restore</code> endpoint. An authenticated user can bypass configuration security constraints by providing a forged backup file. The application fails to strictly validate the contents of the restored backup, allowing an attacker to modify <code>app.ini</code>. By injecting arbitrary commands into the <code>TestConfigCmd</code> field within this configuration file, an attacker can trigger command execution via the <code>POST /api/nginx/test</code> endpoint. This vulnerability allows an attacker to achieve full control over the runtime environment of the Nginx-UI service, potentially leading to unauthorized data access and persistence within the underlying system. This was identified in Nginx-UI versions between 1.9.10-0.20260421071512-7864e378f5cf and 1.9.10-0.20260728074146-a467ed652591.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker authenticates to the target Nginx-UI instance and obtains a valid JWT.</li>
<li>Attacker initiates an authorized backup request to <code>GET /api/backup</code> to retrieve current encrypted backup artifacts and the required <code>X-Backup-Security</code> token.</li>
<li>Attacker decrypts the retrieved backup archive using the extracted security token and IV.</li>
<li>Attacker modifies the <code>app.ini</code> file within the decrypted archive to include a malicious payload in the <code>TestConfigCmd</code> setting.</li>
<li>Attacker re-encrypts the modified backup archive and regenerates the manifest signature using the same HMAC key derivation logic.</li>
<li>Attacker uploads the forged backup via <code>POST /api/restore</code> with the malicious payload included.</li>
<li>Attacker invokes <code>POST /api/nginx/test</code> to force the application to execute the modified <code>TestConfigCmd</code>.</li>
<li>Arbitrary code executes within the Nginx-UI container context, completing the exploit chain.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full command execution within the Nginx-UI runtime environment. An attacker can use this access to read or modify sensitive configuration data, extract JWT secrets, corrupt application state, or move laterally within the host environment, depending on the container's privileges and host integration.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for detection and mitigation:</p>
<ul>
<li>Patch Nginx-UI to version 1.9.10-0.20260728074146-a467ed652591 or later to remediate CVE-2026-107806.</li>
<li>Deploy WAF or web server rules to audit or block <code>POST</code> requests to <code>/api/restore</code> and <code>/api/nginx/test</code> originating from non-administrative user accounts.</li>
<li>Monitor logs for unusual configuration changes, specifically modifications to <code>app.ini</code> or attempts to trigger nginx test command execution from suspicious user sessions.</li>
<li>Restrict access to the Nginx-UI interface to trusted internal networks only to minimize the exposure of administrative endpoints.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>remote-code-execution</category><category>cve-2026-107806</category><category>nginx-ui</category><category>vulnerability</category><category>authentication-bypass</category><category>cve-2026-107808</category><category>web-application</category><category>n8n</category><category>csrf</category><category>cve-2026-107809</category></item></channel></rss>