CVE-2026-107811
Awaiting Analysis Awaiting Analysis - Queue

Authenticated Node Impersonation in Nginx UI

Vulnerability report for CVE-2026-107811, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenticated users can access /api/nodes and /api/nodes/:id, whose responses serialize the node token field. The same token is accepted as X-Node-Secret by AuthRequired and maps the request to initUser, allowing the user to impersonate a trusted node against a reachable cluster member. This cross-node authentication bypass can expose sensitive management operations, including configuration synchronization and service restart. This issue is fixed in version 2.5.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
0xJacky nginx-ui >= 2.0.0, < 2.5.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Nginx UI is a web interface for Nginx. Between versions 2.0.0 and 2.5.0, authenticated users could access endpoints that exposed node tokens. These tokens could be used to impersonate trusted nodes in a cluster, bypassing authentication and allowing unauthorized management operations.

Detection Guidance

Check Nginx UI versions between 2.0.0 and 2.5.0. Inspect network traffic for unauthorized access to /api/nodes or /api/nodes/:id endpoints. Look for suspicious requests using the node token as X-Node-Secret header.

Impact Analysis

An attacker with access could impersonate a trusted node, perform sensitive actions like modifying configurations or restarting services, and potentially gain control over the Nginx server or cluster.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating confidentiality requirements in GDPR and HIPAA. Organizations using affected versions may face compliance violations and legal consequences.

Mitigation Strategies

Upgrade Nginx UI to version 2.5.0 or later immediately. Revoke all node tokens if compromised. Restrict access to /api/nodes endpoints. Monitor for unusual authentication attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107811. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart