{"id":"CVE-2026-107806","summary":"Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite","details":"Nginx UI is a web user interface for the Nginx web server. From 2.3.8 until 2.5.0, an authenticated administrator with an active secure session can submit attacker-controlled portable backup key material and a matching manifest to POST /api/restore. The restore flow trusts the supplied key, decrypts attacker-controlled contents, and replaces the live app.ini, including protected nginx command settings such as TestConfigCmd. Triggering POST /api/nginx/test then executes the restored command in the Nginx UI runtime context, affecting confidentiality, integrity, and availability. This issue is fixed in version 2.5.0.","aliases":["GHSA-p393-cf76-4jmr"],"modified":"2026-10-10T02:47:31.537926158Z","published":"2026-10-09T15:00:55.470Z","database_specific":{"cwe_ids":["CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107806.json","cna_assigner":"GitHub_M"},"references":[{"type":"FIX","url":"https://github.com/0xJacky/nginx-ui/commit/a467ed652591fc0cd1b466a1ec751b493faef9f7"},{"type":"WEB","url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.0"},{"type":"ADVISORY","url":"https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-p393-cf76-4jmr"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107806.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107806"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/0xjacky/nginx-ui","events":[{"introduced":"7864e378f5cf8013c4df38c15e57480f5c2db1d7"},{"fixed":"acb59fdd81dbdd60abd0004e9ade573186a3be43"}],"database_specific":{"extracted_events":[{"introduced":"2.3.8"},{"fixed":"2.5.0"}],"source":"AFFECTED_FIELD"}}],"versions":["v2.4.3","v2.4.2","v2.4.1","v2.4.0","v2.3.11","v2.3.10","v2.3.9","v2.3.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107806.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}