CVE-2026-107809
Awaiting Analysis Awaiting Analysis - Queue

CSRF in Nginx UI Admin Interface

Vulnerability report for CVE-2026-107809, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, AuthRequired accepts a browser-managed token cookie as an API credential after the front end stores the JWT in that cookie. Because management endpoints do not universally require a CSRF token or perform Origin or Referer validation, a remote attacker can induce a logged-in administrator's browser to submit authenticated cross-site state-changing requests, including POST /api/configs. The attack requires an administrator account without OTP/Passkey or a target endpoint that does not require secure-session proof. The attacker cannot read the cross-origin response but can modify Nginx configuration, trigger reloads, or invoke other management operations reachable with the victim's session. This issue is fixed in version 2.5.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
0xJacky nginx-ui >= 2.0.0, < 2.5.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Nginx UI versions 2.0.0 to 2.5.0 have a Cross-Site Request Forgery (CSRF) vulnerability. The application stores an API JWT in a browser cookie named 'token' which is accepted as valid authentication. Management endpoints do not enforce CSRF tokens or Origin/Referer checks, allowing attackers to trick administrators into submitting malicious requests.

Detection Guidance

Check if Nginx UI versions 2.0.0 to 2.4.3 are installed by running: nginx-ui --version or checking package managers like apt list --installed | grep nginx-ui. Inspect browser cookies for a 'token' cookie storing JWT authentication. Monitor network traffic for unauthorized POST requests to /api/configs or other management endpoints without CSRF tokens.

Impact Analysis

An attacker could exploit this to perform unauthorized administrative actions such as modifying Nginx configurations, triggering reloads, changing settings, or manipulating backups. This could lead to traffic redirection, reverse proxy tampering, denial of service, or further server-side impacts if dangerous Nginx modules are enabled.

Compliance Impact

This vulnerability could lead to unauthorized administrative actions on Nginx configurations, potentially exposing sensitive data or disrupting services. For GDPR, this may result in unauthorized access to personal data processing systems. For HIPAA, it could allow tampering with systems handling protected health information. The lack of CSRF protection and Origin/Referer validation increases the risk of such unauthorized access.

Mitigation Strategies

Upgrade Nginx UI to version 2.5.0 or later immediately. Disable the 'token' cookie as an authentication source by reviewing AuthRequired middleware settings. Implement CSRF tokens for all management endpoints and enforce Origin/Referer header validation. Rotate all administrative credentials and JWT secrets if compromised.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107809. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart