CVE-2026-107813
Awaiting Analysis Awaiting Analysis - Queue

Authenticated Node CRUD and Nginx Restart in Nginx UI

Vulnerability report for CVE-2026-107813, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster router exposes node and namespace mutation operations and cluster-wide Nginx reload or restart operations with AuthRequired but without RequireSecureSession. An authenticated OTP-enabled user possessing a stolen or persisted JWT can therefore perform node CRUD, read or replace node credentials, change namespaces, and invoke nodes/reload_nginx or nodes/restart_nginx without a fresh second-factor step-up. This issue is an incomplete fix for CVE-2026-84315 and is fixed in version 2.5.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
0xJacky nginx-ui >= 2.0.0, < 2.5.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-107813 is a vulnerability in Nginx UI versions 2.0.0 to 2.5.0 where the api/cluster router allows sensitive operations like node management and nginx reload/restart with only a JWT. This happens because the router lacks a RequireSecureSession requirement, meaning an attacker with a stolen or persisted JWT can perform these actions without a second-factor step-up.

Detection Guidance

Check if your nginx-ui version is between 2.0.0 and 2.5.0. Review audit logs for unauthorized cluster operations like node CRUD, namespace changes, or nginx reload/restart commands without a fresh OTP step-up. Look for JWT tokens in logs that were used for sensitive actions.

Impact Analysis

An attacker could exploit this to perform unauthorized node CRUD operations, read or replace node credentials, change namespaces, and trigger nginx reload or restart. This could lead to unauthorized access, data breaches, configuration changes, or service disruption.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. It may result in non-compliance due to potential data breaches and lack of proper access controls.

Mitigation Strategies

Upgrade nginx-ui to version 2.5.0 or later. Apply RequireSecureSession middleware to the api/cluster router's mutation handlers. Review and update other handlers like system/restart and core-upgrade for similar issues. Rotate all node secrets and JWT tokens if they may have been exposed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107813. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart