CVE-2026-66362
Received Received - Intake

NGINX Gateway Fabric Configuration Injection Vulnerability

Vulnerability report for CVE-2026-66362, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: F5 Networks

Description

Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the Authentication Filter Custom Resource Definition clientID or cookieName fields, or in the clientSecret field of a Secret referenced by an Authentication Filter, are rendered directly into NGINX configuration templates without sanitization or escaping. Impact: An authenticated attacker with permission to create or modify these resources may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
f5 nginx_plus *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-76 The product correctly neutralizes certain special elements, but it improperly neutralizes equivalent special elements.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an injection flaw in NGINX Gateway Fabric when used with NGINX Plus as the data plane. It allows authenticated attackers with resource modification permissions to inject arbitrary NGINX configuration directives by crafting values in specific fields like clientID, cookieName, or clientSecret without proper sanitization.

Impact Analysis

An attacker could exploit this to alter NGINX configurations, potentially leading to unauthorized access, service disruption, or misconfiguration of network traffic routing. However, it does not directly expose the data plane.

Mitigation Strategies

Update NGINX Gateway Fabric to the latest version that includes fixes for this injection vulnerability. Review and restrict permissions for creating or modifying Authentication Filter Custom Resource Definitions and Secrets to prevent unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66362. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart