OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-107811 (CVSS 8.8)

NVD · officialPublished Oct 9, 2026Risk 37/100

Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenticated users can access /api/nodes and /api/nodes/:id, whose responses serialize the node token field. The same token is accepted as X-Node-Secret by AuthRequired and maps the request to initUser, allowing the user to impersonate a trusted node against a reachable cluster member. This cross-node authentication bypass can expose sensitive management operations, including configuration synchronization and service restart. This issue is fixed in version 2.5.0.

CVSS
8.8
AV:NetworkAC:LowPR:LowUI:NoneC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source