Nginx UI: Authenticated RCE via Backup Restore Config Overwrite (CVE-2026-107806)
What happened
A newly published GHSA advisory (GHSA-p393-cf76-4jmr, CVE-2026-107806) details an authenticated remote code execution flaw in Nginx UI, the Go-based web management interface for nginx. The researcher reports that the POST /api/restore endpoint accepts an attacker-supplied AES key used to derive the backup's signing key, which lets an authenticated user forge a valid encrypted backup archive. That forged backup can overwrite the live app.ini configuration, including protected fields such as TestConfigCmd under the [nginx] section. Once set, triggering POST /api/nginx/test causes Nginx UI to execute the attacker-controlled command string. This was validated against nginx-ui 2.3.11 2(523) 6c86e5a5 running in the uozi/nginx-ui:latest Docker image, with a full proof-of-concept published in the advisory.
Why it matters
This is a privilege-escalation-to-RCE path reachable by any ordinary authenticated Nginx UI user — no admin rights are required to call /api/restore. Because the restore flow writes directly into live application config and database state, successful exploitation gives an attacker command execution in the Nginx UI runtime context, exposure of secrets (node/JWT secrets), and the ability to corrupt or fully take over the management plane for whatever nginx fleet that instance controls. Any organization running self-hosted Nginx UI with multiple authenticated users — or any user accounts of uncertain trust — should treat this as high severity; exploit code is already public.
What defenders should watch for now
- Audit who has valid Nginx UI accounts/JWTs today; this is only exploitable by an authenticated user, so account hygiene and token revocation are the first lever.
- Monitor for unexpected
POST /api/restorecalls, especially from non-admin accounts or paired closely in time with aPOST /api/nginx/testcall. - Watch for unexplained changes to
/etc/nginx-ui/app.ini(or container-mounted equivalents), particularly to the[nginx]section's command fields (TestConfigCmdand similar). - Look for backup/restore API traffic carrying attacker-controlled
security_tokenvalues or backup files that didn't originate from a legitimateGET /api/backupexport. - At a mitigation level: restrict restore functionality to admin-only sessions, disable self-service restore if not required operationally, and ensure Nginx UI instances are not exposed to untrusted or broadly-shared user populations until a fix lands.
Developing intel
This is net-new, same-day intel based on a researcher-published GHSA advisory and proof-of-concept; no CVSS score has been assigned yet and patch status should be confirmed directly against upstream releases. Details may evolve as the maintainers respond. See the original advisory for full technical detail and the PoC: GHSA-p393-cf76-4jmr.