CVE-2026-102335
Received Received - Intake

Nginx Proxy Manager Misconfiguration Allows Arbitrary Nginx Directive Injection

Vulnerability report for CVE-2026-102335, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulnCheck

Description

Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their assigned hosts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nginx_proxy_manager nginx_proxy_manager 2.16.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Nginx Proxy Manager up to version 2.16.0 allows non-admin users with manage permissions to inject arbitrary nginx directives via the advanced_config field. This bypasses intended restrictions and enables attackers to add malicious nginx configurations like alias directives, which can serve arbitrary files or manipulate routing for assigned hosts.

Detection Guidance

Check Nginx Proxy Manager logs for unauthorized changes to advanced_config by non-admin users. Inspect nginx configuration files for unexpected alias directives or malicious nginx directives in host configurations.

Impact Analysis

An attacker with manage permissions could exploit this to serve malicious files, redirect traffic, or gain unauthorized access to sensitive data by altering nginx configurations. This could lead to data breaches, service disruption, or further network compromise depending on the injected directives.

Compliance Impact

This vulnerability could lead to unauthorized access or exposure of sensitive data, violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. Non-compliance may result in legal penalties, fines, or reputational damage.

Mitigation Strategies

Upgrade Nginx Proxy Manager to a version that restricts advanced_config to administrators. Review and remove any unauthorized nginx directives in host configurations. Restrict manage permissions to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102335. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart