logo

Race Against the Clock: The 10-Minute Window Granting Root RCE in Nginx UI

ID: 40abfe8f-16ab-50a1-8b36-209f9c1b0010

STIX ID: report--40abfe8f-16ab-50a1-8b36-209f9c1b0010

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Ddos

...
...

A critical vulnerability (CVE-2026-42238, CVSS 9.0) in Nginx UI allows unauthenticated remote code execution through the POST /api/restore endpoint because the application leaves this endpoint unauthenticated for the first 10 minutes after startup — a window that resets on every restart. An attacker can upload a malicious backup to overwrite app.ini and the SQLite database, inject OS commands that execute after an automatic restart, and potentially gain root-level access in common Docker deployments, exposing nginx configs, TLS keys, and secrets; a patch enforcing unconditional authentication has been released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.