CVE-2026-66362
Awaiting Analysis Awaiting Analysis - Queue

NGINX Gateway Fabric Configuration Injection Vulnerability

Vulnerability report for CVE-2026-66362, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-03

Assigner: F5 Networks

Description

Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the Authentication Filter Custom Resource Definition clientID or cookieName fields, or in the clientSecret field of a Secret referenced by an Authentication Filter, are rendered directly into NGINX configuration templates without sanitization or escaping. Impact: An authenticated attacker with permission to create or modify these resources may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-03
Generated
2026-09-23
AI Q&A
2026-09-02
EPSS Evaluated
2026-09-22
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
f5 nginx_plus *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-76 The product correctly neutralizes certain special elements, but it improperly neutralizes equivalent special elements.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an injection flaw in NGINX Gateway Fabric when used with NGINX Plus as the data plane. It allows authenticated attackers with resource modification permissions to inject arbitrary NGINX configuration directives by crafting values in specific fields like clientID, cookieName, or clientSecret without proper sanitization.

Detection Guidance

To detect this vulnerability, inspect NGINX Gateway Fabric configuration files and Kubernetes resources for Authentication Filter Custom Resource Definitions. Check for untrusted input in clientID, cookieName, or clientSecret fields that may contain NGINX directives. Review logs for unauthorized configuration changes or suspicious NGINX process behavior.

Impact Analysis

An attacker could exploit this to alter NGINX configurations, potentially leading to unauthorized access, service disruption, or misconfiguration of network traffic routing. However, it does not directly expose the data plane.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it is a control plane issue with no data plane exposure. However, unauthorized configuration changes could potentially lead to misconfigurations that might impact compliance indirectly by altering security controls or data handling policies.

Mitigation Strategies

Update NGINX Gateway Fabric to the latest version that includes fixes for this injection vulnerability. Review and restrict permissions for creating or modifying Authentication Filter Custom Resource Definitions and Secrets to prevent unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66362. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart