8.1
/ 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are available.
Basic Information
ID
CVE-2026-42222
Source
GitHub_M
Published
May 4, 2026 at 20:11
Modified
May 4, 2026 at 20:13
Affected Product
Vendor
0xJacky
Product
nginx-ui
Version
= 2.3.5
Affected Versions
0xJacky nginx-ui = 2.3.5