Race Against the Clock: The 10-Minute Window Granting Root RCE in Nginx UI
ID: 40abfe8f-16ab-50a1-8b36-209f9c1b0010
STIX ID: report--40abfe8f-16ab-50a1-8b36-209f9c1b0010
Feed Name: securityonline.info
A critical vulnerability (CVE-2026-42238, CVSS 9.0) in Nginx UI allows unauthenticated remote code execution through the POST /api/restore endpoint because the application leaves this endpoint unauthenticated for the first 10 minutes after startup — a window that resets on every restart. An attacker can upload a malicious backup to overwrite app.ini and the SQLite database, inject OS commands that execute after an automatic restart, and potentially gain root-level access in common Docker deployments, exposing nginx configs, TLS keys, and secrets; a patch enforcing unconditional authentication has been released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
