CVE-2026-107810
Awaiting Analysis Awaiting Analysis - Queue

Path Traversal in Nginx UI

Vulnerability report for CVE-2026-107810, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, internal/backup/restore.go extracts inner archives before applying the restore_nginx and restore_nginx_ui flags and permits symlinks targeting the live Nginx configuration path. An authenticated user who can create and restore backups can craft a valid backup that places a symlink in the staging tree and then writes a regular file through that link, even when both restore flags are false. This can persistently inject configuration or cause denial of service when the modified files are later consumed. This issue is fixed in version 2.5.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
0xJacky nginx-ui >= 2.0.0, < 2.5.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-61 The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Nginx UI versions 2.0.0 to 2.5.0. It involves the backup and restore functionality where an authenticated user can craft a malicious backup containing symlinks. During restoration, the system follows these symlinks into the live Nginx configuration directory before checking restore flags. Even with flags set to false, files can be written to the live configuration path, allowing persistent configuration injection or denial of service.

Detection Guidance

Check for unauthorized symlinks in backup archives or Nginx configuration directories. Inspect backup files before restoration using commands like tar -tvf backup.tar to list contents and identify suspicious symlinks pointing to live Nginx paths.

Impact Analysis

An attacker with backup privileges could modify Nginx configurations, leading to service disruption or unauthorized access. The vulnerability allows persistent changes to the live system, potentially causing denial of service or enabling further attacks through misconfigured Nginx settings.

Compliance Impact

This vulnerability could lead to unauthorized modifications of system configurations, potentially violating integrity and availability requirements in GDPR and HIPAA. Unauthorized changes may result in non-compliance with data protection and security standards.

Mitigation Strategies

Upgrade Nginx UI to version 2.5.0 or later immediately. Review and remove any unauthorized symlinks in Nginx configuration directories. Restrict backup creation and restore privileges to trusted administrators only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107810. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart