← Blog · · df00tech

Nginx UI: Authenticated RCE via Backup Restore Config Overwrite (CVE-2026-107806)

breaking ghsa go CVE-2026-107806

What happened

A newly published GHSA advisory (GHSA-p393-cf76-4jmr, CVE-2026-107806) details an authenticated remote code execution flaw in Nginx UI, the Go-based web management interface for nginx. The researcher reports that the POST /api/restore endpoint accepts an attacker-supplied AES key used to derive the backup's signing key, which lets an authenticated user forge a valid encrypted backup archive. That forged backup can overwrite the live app.ini configuration, including protected fields such as TestConfigCmd under the [nginx] section. Once set, triggering POST /api/nginx/test causes Nginx UI to execute the attacker-controlled command string. This was validated against nginx-ui 2.3.11 2(523) 6c86e5a5 running in the uozi/nginx-ui:latest Docker image, with a full proof-of-concept published in the advisory.

Why it matters

This is a privilege-escalation-to-RCE path reachable by any ordinary authenticated Nginx UI user — no admin rights are required to call /api/restore. Because the restore flow writes directly into live application config and database state, successful exploitation gives an attacker command execution in the Nginx UI runtime context, exposure of secrets (node/JWT secrets), and the ability to corrupt or fully take over the management plane for whatever nginx fleet that instance controls. Any organization running self-hosted Nginx UI with multiple authenticated users — or any user accounts of uncertain trust — should treat this as high severity; exploit code is already public.

What defenders should watch for now

  • Audit who has valid Nginx UI accounts/JWTs today; this is only exploitable by an authenticated user, so account hygiene and token revocation are the first lever.
  • Monitor for unexpected POST /api/restore calls, especially from non-admin accounts or paired closely in time with a POST /api/nginx/test call.
  • Watch for unexplained changes to /etc/nginx-ui/app.ini (or container-mounted equivalents), particularly to the [nginx] section's command fields (TestConfigCmd and similar).
  • Look for backup/restore API traffic carrying attacker-controlled security_token values or backup files that didn't originate from a legitimate GET /api/backup export.
  • At a mitigation level: restrict restore functionality to admin-only sessions, disable self-service restore if not required operationally, and ensure Nginx UI instances are not exposed to untrusted or broadly-shared user populations until a fix lands.

Developing intel

This is net-new, same-day intel based on a researcher-published GHSA advisory and proof-of-concept; no CVSS score has been assigned yet and patch status should be confirmed directly against upstream releases. Details may evolve as the maintainers respond. See the original advisory for full technical detail and the PoC: GHSA-p393-cf76-4jmr.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.