Nginx UI RCE flaw CVE-2026-107806 rated 9.4 Critical
A critical flaw, CVE-2026-107806 (CVSSv4 9.4), was found in the 0xJacky nginx-ui web console: an authenticated admin can achieve remote code execution by uploading a forged configuration backup. Versions 2.3.8 through below 2.5.0 are affected; the fix ships in 2.5.0.
- CVE-2026-107806 is an authenticated RCE rated 9.4 Critical
- Affected: nginx-ui 2.3.8 up to but not including 2.5.0
- Backup signing key derives from attacker-controlled data, defeating integrity checks
- Version 2.5.0 adds strict backup validation and a server-held secret
Read next
Security